# Subcontractor Business Associate Agreement

Version: 2.2, effective October 9, 2026 for new acceptances

Published October 9, 2026. Replaces Version 2.1, effective October 8, 2026. Version 2.2 changes Subcontractor: the Polestar GRC business was assigned to Jonathan Prine, an individual doing business as Polestar GRC, who signs this BAA as Owner. Version 2.2 also replaces the assignment terms in Section 16.7, which now allow one further assignment, to an LLC of which Jonathan Prine is the sole member, only after at least thirty (30) days' Secure Notice and that company's signed assumption; limits Upstream Restrictions to terms on how PHI is handled and lets Subcontractor decline one, with a right for Customer to terminate (Sections 1.5, 2.1 and 9(c)); bars AI training on de-identified data (Section 2.4); names Amazon Web Services as the Downstream Subcontractor for AI features and states which files they send without redaction (Section 2.9); bars access to PHI from outside the United States by Subcontractor's own workforce and contractors (Section 3.3); adds notice immediately following Discovery and a fifteen (15) day target for reports about California residents (Section 5.12); corrects the Part 2 citation (Section 7.2); corrects the insurance statement (Section 12.5); and bars acceptance by a person who works for a referring organization (Section 18.1). This version applies to every acceptance made on or after October 9, 2026. A Customer that accepted an earlier version stays on the version it accepted until it accepts this version (Section 14.5). For a customer that accepted an earlier version, Jonathan Prine became the Subcontractor by assignment on the date stated in our notice of assignment. The assignment right in Section 16.7 applies to that customer only after an administrator accepts this version. Every earlier version is archived at polestargrc.com/legal/archive.

About this document. This Subcontractor Business Associate Agreement is the contract that governs Protected Health Information in the Polestar GRC Service when the customer is itself a business associate: for example a billing company, managed service provider, consultant, or software vendor that handles Protected Health Information for covered entities, or a subcontractor of such a business associate. In that arrangement Polestar is a subcontractor business associate under 45 C.F.R. 160.103, and this document is the written agreement that 45 C.F.R. 164.502(e)(1)(ii), 164.504(e)(5), 164.308(b)(2), and 164.314(a)(2)(iii) require between a business associate and its subcontractor. If your organization is a covered entity (a health care provider, health plan, or health care clearinghouse), do not accept this document; accept the Business Associate Agreement instead. If your organization is a Polestar partner that creates workspaces for its own clients, read Section 10 before accepting. Until this agreement is in place, the Services do not accept new file uploads or the narrative text of incident records in your workspace (Section 9(d)). This document becomes binding on both parties when your organization accepts it electronically. If your organization needs changes to this text, write to legal@polestargrc.com before accepting. We consider reasonable requests.

This Subcontractor Business Associate Agreement ("BAA") is entered into by and between:

- Business Associate: [CUSTOMER LEGAL NAME] ("Business Associate" or "Customer"). Business address: [CUSTOMER ADDRESS]. Customer is identified by its Polestar GRC organization account. Notices to Customer are delivered as described in Section 15, which does not depend on a mailing address being on file.
- Subcontractor: Jonathan Prine, an individual doing business as Polestar GRC, 434 Kern St, Taft, CA 93268 ("Subcontractor", "Polestar GRC" or "Polestar").

Effective Date. This BAA takes effect on the date Customer accepts it electronically, as shown in the Execution Record appended to the executed copy. If Customer accepted an earlier version of this BAA, this version replaces that version on the date described in Section 14.

Relationship to the Agreement. This BAA supplements and is incorporated into the Polestar GRC Terms of Service, or any other written services agreement between the parties that expressly refers to this BAA (the "Agreement"). The Agreement describes the Services. This BAA governs how Subcontractor handles Protected Health Information while providing the Services. If this BAA and the Agreement conflict about Protected Health Information, this BAA controls.

## 1. Definitions

1.1 HIPAA Rules means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended, including by the HITECH Act and its implementing regulations.

1.2 Capitalized terms used but not defined in this BAA have the meanings given in the HIPAA Rules, including Breach, Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information, Health Care Operations, Individual, Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

1.3 Services means the Polestar GRC software-as-a-service platform and related support described in the Agreement, including during a free trial and during the Export Window.

1.4 Upstream Party means each Covered Entity, and each business associate of a Covered Entity, on whose behalf Customer creates, receives, maintains, or transmits PHI that Customer places in the Services. Customer may be a business associate of a Covered Entity or a subcontractor of another business associate; in either case the person on whose behalf Customer acts is an Upstream Party. Upstream BAA means the business associate agreement or subcontractor business associate agreement between Customer and an Upstream Party.

1.5 Upstream Restriction means a restriction or condition in an Upstream BAA, or communicated to Customer by an Upstream Party, on how PHI may be used, disclosed, safeguarded, stored, accessed, reported, or returned or destroyed, that is more restrictive than this BAA and that Customer has identified to Subcontractor in writing under Section 9(c). An Upstream Restriction includes any limitation in a Covered Entity's notice of privacy practices under 45 C.F.R. 164.520, any change in or revocation of an Individual's permission to use or disclose PHI, and any restriction agreed under 45 C.F.R. 164.522, in each case that an Upstream Party has communicated to Customer and that affects Subcontractor's handling of PHI. A term about insurance, indemnity, limitation of liability, penalties, fees, audit costs, or governing law is not an Upstream Restriction. Such a term binds Subcontractor only if it agrees to it in a written amendment under Section 14.4.

1.6 Protected Health Information or PHI means Protected Health Information as defined at 45 C.F.R. 160.103, limited to the PHI that Subcontractor creates, receives, maintains, or transmits on behalf of Customer through the Services. PHI includes Electronic PHI.

1.7 Discovery of a Breach has the meaning in 45 C.F.R. 164.410(a)(2): the first day on which the Breach is known to Subcontractor or, by exercising reasonable diligence, would have been known to Subcontractor. A Breach is treated as known to Subcontractor when it is known to any workforce member or agent of Subcontractor other than the person who committed it.

1.8 Successful Security Incident means a Security Incident that results in unauthorized access to, or unauthorized acquisition, use, disclosure, modification, or destruction of, PHI, or interference with system operations in an information system that contains PHI. It excludes Unsuccessful Security Incidents.

1.9 Unsuccessful Security Incident means an attempted Security Incident that does not result in any of the outcomes listed in Section 1.8, such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, denial of service attacks that do not result in a server being taken offline, and malware that is blocked before execution.

1.10 Part 2 Record means a record, or information in a record, that identifies a patient as having or having had a substance use disorder and that is subject to 42 C.F.R. Part 2.

1.11 Business Day means Monday through Friday, excluding United States federal holidays.

1.12 Partner, Client, Client Workspace, and Sandbox Workspace have the meanings given in Section 10.1.

1.13 Secure Notice means a notice delivered inside the Services to an authenticated administrator of Customer's organization account, together with an email to the contacts in Section 15.1 that states that a notice is waiting and how to reach it, and that does not itself contain PHI.

## 2. Permitted and Required Uses and Disclosures

2.1 Services. Subcontractor may use and disclose PHI to provide, support, secure, and maintain the Services for Customer as described in the Agreement and as Customer directs through the Services. Subcontractor will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Covered Entity whose PHI it is, except as permitted by Sections 2.2 and 2.3. In addition, Subcontractor agrees to the same restrictions and conditions that apply to Customer with respect to PHI, as required by 45 C.F.R. 164.504(e)(2)(ii)(D) and 164.504(e)(5), and will comply with each Upstream Restriction that it has not declined under Section 9(c), from the date Customer identifies it, with respect to the PHI it covers. Sections 2.2 through 2.4 are subject to any Upstream Restriction that limits them.

2.2 Management and administration. Subcontractor may use PHI for its proper management and administration or to carry out its legal responsibilities, as permitted by 45 C.F.R. 164.504(e)(4). Subcontractor may disclose PHI for those purposes only if (a) the disclosure is Required by Law, or (b) Subcontractor first obtains reasonable written assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the recipient, and that the recipient will notify Subcontractor of any instance of which it becomes aware in which the confidentiality of the PHI has been breached. Customer represents that its Upstream BAAs permit Customer to use and disclose PHI for its own proper management and administration and legal responsibilities. If an Upstream BAA does not, Customer will identify that as an Upstream Restriction before placing the affected PHI in the Services, and Subcontractor will not rely on this Section 2.2 for the affected PHI.

2.3 Data Aggregation. Subcontractor may use PHI to provide Data Aggregation services relating to the Health Care Operations of a Covered Entity only if Customer requests those services in writing and confirms in writing that the applicable Upstream BAAs permit them.

2.4 De-identification. Subcontractor may de-identify PHI in accordance with 45 C.F.R. 164.514(a) through (c) only if Customer confirms in writing (including through an organization setting in the Services, where the Services provide one) that the applicable Upstream BAAs permit Customer to de-identify that PHI. Absent that confirmation, Subcontractor will not de-identify PHI for its own purposes. Information de-identified as permitted by this Section is no longer PHI, and Subcontractor may use it to operate, benchmark, secure, and improve the Services. Subcontractor will not attempt to re-identify de-identified information and will not disclose any re-identification code or mechanism. Subcontractor will not use de-identified information derived from PHI to train, fine-tune, or evaluate any artificial intelligence or machine learning model, and will not sell or license it to any third party.

2.5 Required by Law. Subcontractor may use or disclose PHI as Required by Law. Unless legally prohibited, Subcontractor will notify Customer before complying with a subpoena, court order, warrant, or other legal demand for PHI, and will give Customer a reasonable opportunity to object or seek a protective order and to coordinate with the Upstream Party.

2.6 Prohibited uses and disclosures. Subcontractor will not (a) sell PHI or receive remuneration in exchange for PHI, except as permitted by 45 C.F.R. 164.502(a)(5)(ii); (b) use or disclose PHI for marketing or fundraising; (c) use PHI to train, fine-tune, or improve any artificial intelligence or machine learning model, or permit any of its own subcontractors to do so; or (d) use or disclose PHI for any purpose not expressly permitted by this BAA.

2.7 Minimum necessary. Subcontractor will request, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose, consistent with 45 C.F.R. 164.502(b) and 164.514(d), and will apply role-based access so that its workforce members can access only the PHI needed for their roles.

2.8 Obligations of a Covered Entity performed by Subcontractor. To the extent Subcontractor carries out any obligation of a Covered Entity under Subpart E of 45 C.F.R. Part 164, Subcontractor will comply with the requirements of Subpart E that apply to the Covered Entity in the performance of that obligation.

2.9 AI features. The Services include features that send content to a large language model operated by a third-party provider (the "AI Provider"). For every AI feature, Subcontractor (a) sends content only to models hosted on Amazon Bedrock under Subcontractor's business associate agreement with Amazon Web Services, which is a Downstream Subcontractor under Section 4; the model developer does not receive or have access to the content; (b) does not permit the AI Provider to retain content for training or to use it for any purpose other than returning a response; and (c) does not use the content to train any model, consistent with Section 2.6(c). The AI features work in two ways:

(i) Text features (the support chat assistant, policy drafting, and risk analysis answer suggestions) send text that Customer's users type or that the Services assemble from Customer's workspace. Before transmission Subcontractor applies automated, pattern-based redaction to that text. As of the date of this version the redaction covers Social Security numbers, telephone numbers, dates of birth, labeled medical record numbers, and payment card numbers in all text features, and also email addresses, street addresses, and personal names in the support chat assistant. In the other text features it does not remove names, email addresses, or free-text descriptions. Redaction is not guaranteed to remove every identifier.

(ii) Document analysis features send a document or image that Customer's user selects for analysis to the AI Provider. A PDF file or image is sent as uploaded, without redaction. A text file (plain text, CSV, JSON or HTML) is sent after redaction of the patterns that clause (i) lists for the support chat assistant.

Customer agrees that its users will not enter patient-identifying information into text features, will use document analysis only on documents Customer is permitted to disclose to Subcontractor under this BAA and its Upstream BAAs, and will not submit Part 2 Records to any AI feature (Section 7.4). The hosting platform and the model developer are named in the Polestar GRC Privacy Policy, and a change is subject to Section 4.2.

## 3. Safeguards

3.1 Security Rule. Subcontractor will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to Electronic PHI, and will use appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided by this BAA.

3.2 Specific controls. Without limiting Section 3.1, Subcontractor maintains: encryption of PHI in transit (TLS 1.2 or higher) and at rest (AES-256); organization-scoped and role-based access controls enforced on every application procedure; multi-factor authentication available to all users, with organization-wide enforcement available to Customer's administrators; brute-force lockouts; audit logging of access to PHI, protected so that application users, including Customer's own administrators, cannot alter or delete entries, and retained as described in Section 11.5; time-limited, signed download links for uploaded files; and a documented incident response plan tested at least annually.

3.3 Data location and access. Subcontractor stores and processes PHI only in data centers located in the United States and will not transfer PHI outside the United States without Customer's prior written consent. Subcontractor will not permit PHI to be accessed or viewed from outside the United States by its own workforce or contractors without Customer's prior written consent. The locations where each Downstream Subcontractor processes PHI are stated in the Privacy Policy list under Section 4.2.

3.4 Risk analysis. Subcontractor performs and documents an accurate and thorough assessment of risks to the confidentiality, integrity, and availability of Electronic PHI at least annually and after any material change to the Services, as required by 45 C.F.R. 164.308(a)(1)(ii)(A).

3.5 Workforce. Subcontractor ensures that each workforce member with access to PHI is bound by written confidentiality obligations, completes privacy and security training before access and at least annually, and is subject to sanctions for violations of this BAA.

3.6 Documentation. Subcontractor maintains the policies, procedures, and documentation required by 45 C.F.R. 164.316 and retains them for six (6) years from the later of their creation or the date they were last in effect.

3.7 Assurances. On Customer's written request, not more than once in any twelve (12) month period unless following a Breach, Subcontractor will provide a summary of its most recent risk analysis, a description of its security program, a completed security questionnaire of reasonable length, and copies of any third-party security assessments or certifications it holds. Customer may share this material with an Upstream Party under confidentiality obligations in order to satisfy Customer's own due diligence duties, and will otherwise treat it as Subcontractor's confidential information.

## 4. Subcontractor's Own Subcontractors

4.1 Written agreements. Before any person or entity that is a subcontractor of Subcontractor creates, receives, maintains, or transmits PHI on Subcontractor's behalf (a "Downstream Subcontractor"), Subcontractor will enter into a written agreement with that Downstream Subcontractor that meets the requirements of 45 C.F.R. 164.504(e) and 164.314(a) and imposes restrictions and conditions at least as restrictive as those that apply to Subcontractor under this BAA, including each Upstream Restriction that affects the PHI the Downstream Subcontractor handles and compliance with the Security Rule with respect to Electronic PHI, as required by 45 C.F.R. 164.502(e)(1)(ii), 164.504(e)(5), and 164.308(b)(2). Subcontractor will not send PHI to a service provider that has not signed such an agreement, and configures service providers that have not (for example, its email delivery provider Twilio SendGrid, its SMS provider Twilio, and any error monitoring provider) so that PHI is not sent to them. Subcontractor's emails and SMS messages state only that an item is waiting and how to reach it in the Services, and do not contain PHI or text that Customer's users typed.

4.2 Current list and notice. A current list of Downstream Subcontractors that may access PHI, and of service providers that are configured so that PHI does not reach them, is published in the Polestar GRC Privacy Policy. Subcontractor will give Customer at least thirty (30) days' notice by Secure Notice before a new Downstream Subcontractor accesses PHI, so that Customer can meet any notice or consent obligation under its Upstream BAAs. If Customer objects on reasonable grounds related to the protection of PHI within that period and the parties cannot resolve the objection, Customer may terminate the Agreement and this BAA on written notice and Subcontractor will refund any prepaid fees for the period after termination. Subcontractor may replace a Downstream Subcontractor without the thirty (30) day period where necessary to respond to a Security Incident or the Downstream Subcontractor's own failure, and will give notice as soon as practicable afterward.

4.3 Responsibility; pattern of violations. Subcontractor remains responsible to Customer for the acts and omissions of its Downstream Subcontractors with respect to PHI as if they were Subcontractor's own, and will report to Customer any Downstream Subcontractor Security Incident or impermissible use or disclosure under Section 5 as if it had occurred at Subcontractor. If Subcontractor knows of a pattern of activity or practice of a Downstream Subcontractor that constitutes a material breach or violation of the Downstream Subcontractor's obligations, Subcontractor will take reasonable steps to cure the breach or end the violation and, if those steps are unsuccessful, will terminate the arrangement with that Downstream Subcontractor if feasible, as required by 45 C.F.R. 164.504(e)(1)(iii).

4.4 Annual confirmation. On Customer's written request, not more than once in any twelve (12) month period, Subcontractor will confirm in writing that each Downstream Subcontractor listed under Section 4.2 is under a written agreement meeting Section 4.1.

## 5. Reporting

5.1 Reportable Events. Each of the following is a "Reportable Event": (a) a Breach of Unsecured PHI; (b) any acquisition, access, use, or disclosure of PHI not permitted by this BAA, including one that Subcontractor has not yet assessed under Section 5.3; and (c) a Successful Security Incident. A Reportable Event is discovered on the first day on which it is known to Subcontractor or, by exercising reasonable diligence, would have been known to Subcontractor, determined in the same way as Section 1.7 provides for a Breach ("Discovery").

5.2 Initial notice. Subcontractor will notify Customer of a Reportable Event without unreasonable delay and in no case later than seven (7) calendar days after Discovery. Subcontractor will not delay the initial notice to complete its investigation or its risk assessment. One notice may cover an event that falls under more than one part of Section 5.1. The initial notice will state the date of Discovery and will include, to the extent then known: a description of what happened, including the date of the event; the types of PHI involved; the identification of each Individual whose PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; the Upstream Party or Parties whose PHI is involved, where Subcontractor can determine this from the organization of Customer's data in the Services; the steps Individuals should take to protect themselves; what Subcontractor is doing to investigate, mitigate harm, and prevent recurrence; and a contact for further questions. If the person who normally gives notices for Subcontractor is unavailable, the initial notice may be given by a person Subcontractor has designated for that purpose who has no access to PHI; such a notice may state only that Subcontractor is investigating a possible Reportable Event, its date of Discovery, and that the details will follow under Section 5.3. A security alert or anomaly that Subcontractor is investigating, and that has not yet given Subcontractor reason to believe that PHI was or may have been accessed, acquired, used, disclosed, modified, or destroyed without authorization, is not by itself a Reportable Event. Subcontractor will investigate such alerts promptly.

5.3 Risk assessment and full report. Subcontractor will treat each event under Section 5.1(b) as a presumed Breach unless it documents a risk assessment under 45 C.F.R. 164.402 showing a low probability that the PHI has been compromised. No later than thirty (30) calendar days after Discovery, or sooner where reasonably necessary for Customer to meet a shorter notification deadline under an Upstream BAA or state law that Customer identifies under Section 5.12, Subcontractor will deliver a written report that includes its risk assessment and the information described in 45 C.F.R. 164.404(c) and 164.410(c), and will supplement it promptly as more information becomes available. Customer may share the report and risk assessment with the affected Upstream Party. An event that the risk assessment shows is not a Breach remains reportable under this Section 5. Customer and the Upstream Party make the final determination whether notification to Individuals, the Secretary, or the media is required, and Subcontractor will provide the information and cooperation reasonably needed for those notifications, including direct cooperation with an Upstream Party if Customer requests it.

5.4 Outer limits. The seven (7) day and thirty (30) day periods in this Section 5 are outer limits, not targets. They do not extend any shorter period that applicable law requires of Subcontractor, including state laws that require a person that maintains data it does not own to notify the owner immediately or within a fixed number of days, and they do not extend the sixty (60) calendar day limit in 45 C.F.R. 164.410(b). Section 5.7 (law enforcement delay) applies to every period in this Section 5.

5.5 Unsuccessful Security Incidents. The parties acknowledge that this Section 5.5 constitutes notice by Subcontractor of the ongoing occurrence of Unsuccessful Security Incidents. No further notice of Unsuccessful Security Incidents is required. On written request, not more than quarterly, Subcontractor will provide a summary of Unsuccessful Security Incidents affecting systems that hold Customer's PHI.

5.6 Contingency plan activation. Subcontractor will notify Customer within twenty-four (24) hours after activating its contingency plan (for example, restoring from backup or failing over to alternate infrastructure) where the activation affects the availability or integrity of Customer's PHI.

5.7 Law enforcement delay. If a law enforcement official states to Subcontractor that a notification would impede a criminal investigation or damage national security, Subcontractor may delay the notice as permitted by 45 C.F.R. 164.412 and will document the statement and notify Customer as soon as the delay ends.

5.8 Mitigation. Subcontractor will mitigate, to the extent practicable, any harmful effect known to Subcontractor of a use or disclosure of PHI by Subcontractor or its Downstream Subcontractors in violation of this BAA.

5.9 Costs of notification. To the extent a Breach is caused by Subcontractor's or its Downstream Subcontractors' breach of this BAA, Subcontractor will reimburse Customer's reasonable, documented, out-of-pocket costs of the notifications to Individuals, the Secretary, the media, and Upstream Parties that the HIPAA Rules, Customer's Upstream BAAs, or applicable state law require, subject to Section 12.

5.10 Independent contractor; Discovery date. Subcontractor is an independent contractor and not an agent of Customer or of any Upstream Party. Subcontractor controls the manner and means of performing the Services, and Customer directs only the result through the features of the Services. Neither party intends that Subcontractor's knowledge of a Breach be imputed to Customer or any Upstream Party under 45 C.F.R. 164.404(a)(2) or 164.410(a)(2). Because that question is determined under the Federal common law of agency and not by this BAA, Customer should treat Subcontractor's date of Discovery as a possible start of Customer's own notification period until Customer has concluded otherwise, and Subcontractor's seven (7) day notice period under Section 5.2 is designed to keep the difference between the two dates small. Each notice under Section 5.2 will state Subcontractor's date of Discovery.

5.11 How reports are delivered. Subcontractor delivers reports under this Section 5 by Secure Notice to the Privacy Officer and Security Officer contacts recorded in Customer's organization settings and to the organization account owner. The email part of a Secure Notice states that a report is waiting, its date, and how to reach it, and does not contain the identity of any Individual or other PHI. If Customer cannot reach the report in the Services, Subcontractor will deliver it by another method that protects PHI, such as an encrypted file or a telephone call, as Customer reasonably requests. Subcontractor will ask the recipient to confirm receipt of each report. Customer is responsible for keeping those contacts current and for relaying notices to Upstream Parties as its Upstream BAAs require. If no Privacy Officer or Security Officer is recorded, notice to the account owner is sufficient.

5.12 Shorter deadlines under state law or Upstream BAAs. Where PHI in the Services includes personal information that Subcontractor maintains but does not own, Subcontractor's notice under this Section 5 is also its notice to Customer under Cal. Civ. Code 1798.82(b) and similar state laws, and Subcontractor will give it immediately following Discovery, and in any case within the period in Section 5.2. If an Upstream BAA or a state law that applies to Customer requires Customer to receive notice from its subcontractors in less than the seven (7) calendar days in Section 5.2, Customer will identify that deadline as an Upstream Restriction and Subcontractor will use reasonable efforts to meet it. Where Subcontractor knows that the affected PHI concerns residents of California, Subcontractor will use reasonable efforts to deliver the report under Section 5.3 within fifteen (15) calendar days after Discovery, so that the owner of the information can meet Cal. Civ. Code 1798.82(a)(2) and, where it applies, Cal. Health and Safety Code 1280.15(b).

## 6. Individual Rights

6.1 Designated Record Set. The Services are a compliance documentation platform. They are not designed to serve as a medical record or other Designated Record Set, and Customer agrees not to use them as one. The remainder of this Section 6 applies to the extent Subcontractor nonetheless maintains PHI in a Designated Record Set on behalf of Customer.

6.2 Access. Within ten (10) Business Days after Customer's written request, Subcontractor will make PHI in a Designated Record Set available to Customer in the form and format requested if readily producible, or otherwise in a readable electronic form, so that Customer and the Upstream Party can meet their obligations under 45 C.F.R. 164.524. Customer may also use the Services' export features for this purpose at any time.

6.3 Amendment. Within ten (10) Business Days after Customer's written request, Subcontractor will make PHI in a Designated Record Set available for amendment and will incorporate any amendment Customer directs, in accordance with 45 C.F.R. 164.526.

6.4 Accounting of disclosures. Subcontractor will document each disclosure of PHI that would be required to be included in an accounting under 45 C.F.R. 164.528, including the date, the recipient, a brief description of the PHI, and the purpose, and will retain that documentation for six (6) years. Within ten (10) Business Days after Customer's written request, Subcontractor will provide the information needed for Customer and the Upstream Party to respond to an Individual's request for an accounting.

6.5 Restrictions and limitations. Customer will identify as an Upstream Restriction any restriction on use or disclosure of PHI under 45 C.F.R. 164.522, any limitation in a Covered Entity's notice of privacy practices, and any revocation of an Individual's authorization, of which Customer has been informed by an Upstream Party and that affects Subcontractor's handling of PHI, and Subcontractor will comply with it to the extent it applies to the Services.

6.6 Requests received directly. If an Individual or an Upstream Party contacts Subcontractor directly to exercise a right under Subpart E, Subcontractor will forward the request to Customer within five (5) Business Days and will not respond substantively except as Customer directs or as Required by Law.

## 7. Part 2 Records

7.1 Not designed for Part 2 Records. The Services are not designed to store Part 2 Records. Customer will not upload Part 2 Records except where strictly necessary as compliance evidence, and will redact patient identifying information from such records wherever possible before upload.

7.2 Part 2 terms. If Customer is a lawful holder of Part 2 Records under 42 C.F.R. 2.11 (for example because it received them from a Part 2 program, a Covered Entity, or a business associate under a consent for treatment, payment, or health care operations) and places those records in the Services, then with respect to those records Subcontractor acknowledges and agrees, consistent with 42 C.F.R. 2.33(b)(1), and as 42 C.F.R. 2.33(c) would require if it applied to Customer, that:

(a) in receiving, storing, processing, or otherwise dealing with any Part 2 Records, it is fully bound by the provisions of 42 C.F.R. Part 2 upon receipt of the patient identifying information;

(b) it will implement appropriate safeguards to prevent unauthorized uses and disclosures of Part 2 Records, including the safeguards in Section 3;

(c) it will report to Customer under Section 5 any unauthorized use, disclosure, or breach of Part 2 Records;

(d) if it discloses Part 2 Records as permitted by 42 C.F.R. Part 2 and this BAA, it will accompany the disclosure with the notice required by 42 C.F.R. 2.32;

(e) it will not redisclose Part 2 Records except to a Downstream Subcontractor that is helping Subcontractor provide the Services under this BAA and that is bound in writing to disclose the information only back to Subcontractor or Customer, and otherwise only as permitted by 42 C.F.R. Part 2 and this BAA;

(f) it will, if necessary, resist in judicial proceedings any efforts to obtain access to patient identifying information related to substance use disorder diagnosis, treatment, or referral for treatment except as permitted by 42 C.F.R. Part 2; and

(g) it will not use or disclose Part 2 Records in any civil, criminal, administrative, or legislative investigation or proceeding against the patient except as permitted by 42 C.F.R. Part 2.

7.3 Breach notification for Part 2 Records. A Breach involving Part 2 Records is reported under Section 5, and Subcontractor will cooperate with Customer's and the Upstream Party's obligations under 42 C.F.R. 2.16 and 45 C.F.R. 164.400 through 164.414.

7.4 AI features. Customer will not submit Part 2 Records to any AI feature of the Services.

7.5 Customer responsibilities. Customer is responsible for confirming that its receipt of Part 2 Records, and its further disclosure of them to Subcontractor, is permitted by 42 C.F.R. Part 2 and by its Upstream BAAs, and for identifying records as Part 2 Records when uploading them where the Services provide a means to do so.

## 8. Access by the Secretary

Subcontractor will make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Subcontractor on behalf of, Customer available to the Secretary for purposes of determining Customer's, the Upstream Parties', and Subcontractor's compliance with the HIPAA Rules. Unless prohibited by law, Subcontractor will promptly notify Customer of any such request.

## 9. Customer Obligations

Customer represents and agrees that it will:

(a) be a business associate (or a subcontractor business associate) of each Upstream Party whose PHI it places in the Services, and have in place an Upstream BAA that permits Customer to engage subcontractors for the Services, or obtain any consent to subcontracting that its Upstream BAAs require, before placing PHI in the Services;

(b) not place PHI in the Services, and not request Subcontractor to use or disclose PHI, in any manner that would violate the HIPAA Rules or Customer's Upstream BAAs;

(c) identify each Upstream Restriction to Subcontractor in writing before placing the affected PHI in the Services, or within five (5) Business Days after Customer learns of it where it arises later, using the restriction fields in Customer's organization settings where the Services provide them and otherwise by notice under Section 15.2. Subcontractor is bound by each Upstream Restriction from the date it is identified, unless within ten (10) Business Days Subcontractor tells Customer in writing that it cannot or will not meet it. In that case Customer will not place the affected PHI in the Services, and will remove any affected PHI already there, unless the parties agree in writing how the Upstream Restriction will be met. Customer may then terminate the Agreement and this BAA on written notice and receive a refund of prepaid fees for the period after termination. Apart from the HIPAA Rules, this BAA and the Upstream Restrictions it has not declined, Subcontractor is bound by no term of an Upstream BAA;

(d) not upload PHI before this BAA is in effect, upload PHI only within features designed to hold it (evidence uploads, incident records, and document storage), only to the extent reasonably necessary for compliance documentation, and use AI features only as permitted by Section 2.9. Until this BAA has been accepted under Section 18, the Services refuse new file uploads and the narrative text of incident records in Customer's workspace, give incident records a title made from their date and category, and offer acceptance in the same dialog; they never block viewing, downloading (including audit package and evidence ZIP files), or deleting what is already stored. Customer will not place PHI in the Services by any other route, or in fields that block does not cover, before this BAA is in effect;

(e) manage its own users' access to the Services, including removing users who leave its workforce, and keep its Privacy Officer, Security Officer, and account owner contacts current;

(f) relay reports received under Section 5 to the affected Upstream Parties as its Upstream BAAs require;

(g) if Customer is a Partner, comply with Section 10; and

(h) comply with the HIPAA Rules and applicable state law in its own use of the Services and the PHI stored in them.

## 10. Partner Workspaces

10.1 Definitions and scope. A "Partner" is a Customer that has entered into a Partner Agreement with Subcontractor and that Subcontractor has enabled under Section 26 of the Terms of Service to create and manage organization accounts in the Services for its own clients. This Section 10 applies only while a Customer is enabled as a Partner. As of the date of this version, partner features are switched off for every organization until a Partner Agreement is in place. A "Client" is a person for whom a Partner creates an organization account. A "Client Workspace" is that organization account. A "Sandbox Workspace" is a workspace the Services designate for demonstration or training.

10.2 Whose PHI. PHI in a Client Workspace is the Client's PHI (or, if the Client is itself a business associate, the PHI of the Client's own upstream covered entities). Subcontractor creates, receives, maintains, and transmits that PHI on behalf of the Client. The Partner's management of the Client Workspace through the Services (creating the workspace, assigning a plan, viewing aggregate metrics, and billing) does not by itself make the Partner a business associate of the Client with respect to that PHI.

10.3 Client's own agreement required. If a Client is a Covered Entity or a business associate, the Client must accept the Business Associate Agreement or this BAA, as applicable to its role, in its own Client Workspace before PHI is placed there. The Services enforce this in a Client Workspace in the same way as in any other workspace: they refuse new file uploads and the narrative text of incident records until the Client's own administrator accepts the agreement. That agreement is between Subcontractor and the Client, and it, not this BAA, governs all PHI in the Client Workspace, whoever placed it there, including PHI that the Partner's staff enter after the Client invites them. The Partner will not place PHI in a Client Workspace, and will not permit or encourage the Client to do so, until the Client has accepted its agreement. If a Client operates outside HIPAA, the Data Protection Agreement for state mode applies to the Client Workspace instead.

10.4 Partner access to Client PHI. If a Client invites the Partner's workforce into the Client Workspace, or otherwise discloses PHI to the Partner, and the Partner creates, receives, maintains, or transmits that PHI, the Partner is responsible for having its own business associate agreement with the Client covering the Partner's services. That does not change Section 10.3: PHI in a Client Workspace remains governed by the Client's own agreement with Subcontractor. This BAA governs only PHI that the Partner places in its own workspace or otherwise keeps in the Services outside any Client Workspace. With respect to a Client's PHI that the Partner places in its own workspace, the Client is an Upstream Party of the Partner and Sections 9(a) through 9(c) apply.

10.5 Sandbox Workspaces. Sandbox Workspaces are not designed to hold PHI. The Partner will not place PHI in a Sandbox Workspace and will not permit others to do so. This BAA does not apply to information in a Sandbox Workspace except that Subcontractor will treat any PHI it discovers there as PHI and report its discovery to the Partner under Section 5.2.

10.6 Detachment and transfer. If a Client Workspace is detached from the Partner, or the Client leaves the Partner, the Client's own agreement under Section 10.3 continues to govern the Client Workspace, the Partner's access to it ends, and nothing in this BAA requires Subcontractor to return or destroy the Client's PHI at the Partner's request. If the Partner's Agreement or its Partner Agreement terminates, Subcontractor will continue to provide the Services to each Client under the Client's own agreement and may contact the Client directly about billing and continuity. Section 11.4 applies only to PHI that the Partner itself placed in its own workspace.

10.7 No acceptance on a Client's behalf. The Partner, and anyone whose access to a Client Workspace comes through the Partner, may not accept the Business Associate Agreement, this BAA, the Data Protection Agreement, or the Terms of Service on behalf of a Client, and the Services refuse such an acceptance.

## 11. Term and Termination

11.1 Term. This BAA takes effect on the Effective Date and remains in effect until the later of (a) termination or expiration of the Agreement, and (b) the date Subcontractor has returned or destroyed all PHI as provided in Section 11.4 or has documented that return or destruction is infeasible under Section 11.5.

11.2 Termination for cause by Customer. If Customer determines that Subcontractor has violated a material term of this BAA, Customer may (a) give Subcontractor written notice describing the violation and terminate this BAA and the Agreement if Subcontractor does not cure the violation within thirty (30) days after the notice, or (b) terminate this BAA and the Agreement immediately on written notice if cure is not possible. Subcontractor will refund any prepaid fees for the period after a termination under this Section 11.2.

11.3 Termination for cause by Subcontractor. If Subcontractor determines that Customer has violated a material term of this BAA, including by placing PHI in the Services in a manner that breaches Section 9 or Section 10 and that materially increases risk to PHI, Subcontractor may give Customer written notice describing the violation and may suspend the affected features or terminate this BAA and the Agreement if Customer does not cure within thirty (30) days after the notice.

11.4 Return or destruction; Upstream terminations. On termination or expiration of the Agreement for any reason, Customer may export its PHI using the Services' export features for thirty (30) days (the "Export Window"). After the Export Window, Subcontractor will destroy all PHI it maintains on behalf of Customer, including PHI held by Downstream Subcontractors, using methods consistent with NIST Special Publication 800-88, and will retain no copies, except as provided in Section 11.5. Destruction of PHI in production systems will be complete within thirty (30) days after the Export Window, and destruction of PHI in encrypted backups will be complete within ninety (90) days after the Export Window as backup media reach the end of their rotation. Subcontractor will send a written certification of destruction to the account owner's email address when production destruction is complete and again when backup destruction is complete, and will provide a further certification on request. Customer may instead request return of PHI in a commonly used electronic format before the Export Window ends. If an Upstream BAA terminates while the Agreement continues, Customer is responsible for deleting or exporting the affected Upstream Party's PHI from the Services using the Services' features, and may ask Subcontractor to confirm destruction of that PHI on the same schedule.

11.5 Infeasibility. If return or destruction of specific PHI is infeasible, Subcontractor will notify Customer of the conditions that make it infeasible, extend the protections of this BAA to that PHI, limit further uses and disclosures to the purposes that make return or destruction infeasible, and destroy the PHI when those purposes end. The parties agree that return or destruction is infeasible only for (a) audit log entries that Subcontractor retains for six (6) years under 45 C.F.R. 164.316(b)(2), which record the identity of the user, the action taken, the type and identifier of the record affected, the network address, and the time, together with any PHI embedded in those entries (for example in a file name or record title), which Subcontractor will destroy when the six (6) year retention period ends, and (b) PHI subject to a litigation hold or legal preservation obligation, which Subcontractor will destroy when the hold ends.

11.6 Suspension. Suspension of the Services under the Agreement does not suspend Subcontractor's obligations under this BAA. During a suspension, Subcontractor will continue to safeguard PHI and, where the suspension is not for Customer's violation of this BAA or a security threat, will preserve Customer's ability to export PHI.

11.7 Survival. Sections 2, 3, 5, 6, 7, 8, 10.6, 11.4, 11.5, 12, 13, and 16 survive termination of this BAA for as long as Subcontractor or any Downstream Subcontractor retains PHI, and Sections 12 and 13 survive indefinitely.

11.8 Lapsed trials. This BAA applies during a free trial. If a free trial ends without a paid subscription, the Export Window in Section 11.4 runs from the end of the trial, and destruction of PHI in production systems will be complete no later than sixty (60) days after the trial ended, unless Customer starts a subscription first; destruction in backups follows Section 11.4.

## 12. Liability, Indemnification, and Insurance

12.1 Relationship to the Agreement. The limitations and exclusions of liability in the Agreement apply to this BAA except as modified in this Section 12. This Section 12 governs liability relating to PHI.

12.2 Direct damages. The following are direct damages, and not consequential or indirect damages, when they are caused by a party's breach of this BAA: the reasonable, documented costs of investigating a Breach, including forensic services; the costs of notifying Individuals, the Secretary, the media, state regulators, and Upstream Parties as required by law or by Customer's Upstream BAAs; the cost of call center and credit monitoring or identity protection services where required by law or reasonably necessary to mitigate harm to Individuals; and, to the extent recovery is permitted by applicable law, civil monetary penalties or settlement amounts that a government authority imposes on the non-breaching party and that are attributable to the breaching party's breach of this BAA.

12.3 Indemnification. Each party (the "Indemnifying Party") will defend the other party and its officers, directors, and employees against any third-party claim (including a claim by an Upstream Party), and any investigation or enforcement action by a government authority, arising from the Indemnifying Party's or its subcontractors' breach of this BAA or violation of the HIPAA Rules, and will pay the resulting damages, penalties, settlements, and reasonable attorneys' fees, in each case to the extent permitted by applicable law. The indemnified party will give prompt notice of the claim, allow the Indemnifying Party to control the defense and settlement (provided no settlement admits fault on the indemnified party's behalf or imposes obligations on it without its consent), and cooperate reasonably.

12.4 BAA liability cap. Each party's total aggregate liability arising out of or relating to this BAA, including under Sections 5.9, 12.2, and 12.3, will not exceed the greater of (a) two (2) times the fees paid or payable by Customer under the Agreement in the twelve (12) months before the event giving rise to liability, or (b) fifty thousand U.S. dollars ($50,000), which becomes one hundred thousand U.S. dollars ($100,000) for an event that occurs on a date when the cyber liability insurance stated in Section 12.5 has an aggregate limit of two million U.S. dollars ($2,000,000) or more. This cap is separate from and in addition to the general liability cap in the Agreement. Nothing in this Section 12 limits liability for a party's gross negligence, willful misconduct, or fraud, or liability that cannot be limited under applicable law. Subcontractor is not liable for amounts Customer owes an Upstream Party under an Upstream BAA to the extent they exceed what Customer could recover from Subcontractor under this Section 12.

12.5 Insurance. Subcontractor will state in this Section 12.5 the insurance it carries, will keep that statement accurate, and will provide a certificate of insurance on request. As of the date of this version, Subcontractor does not carry commercial general liability, cyber liability, or technology errors and omissions insurance in its own name, and this BAA does not promise that it does. Subcontractor will give Customer Secure Notice within thirty (30) days after it binds any of those coverages, stating the type of coverage and its limits.

## 13. Governing Law

This BAA is governed by the laws of the State of California and applicable federal law, without regard to conflict-of-laws rules, and the venue and dispute resolution provisions of the Agreement (in the Terms of Service, Sections 22 and 23) apply to it. The parties will interpret and perform this BAA so as to comply with the HIPAA Rules. Nothing in this BAA prevents either party from complying with a state law that is more stringent than the HIPAA Rules and that applies to the PHI in the Services, including the California Confidentiality of Medical Information Act (Cal. Civ. Code 56 et seq.) and state breach notification laws, and the parties will cooperate so that each can meet those state law and Upstream BAA obligations, including shorter breach notification deadlines that Customer identifies to Subcontractor under Section 5.12.

## 14. Amendments and Versions

14.1 Changes in law. The parties will amend this BAA as necessary to comply with changes in the HIPAA Rules or other applicable law. Subcontractor may make those amendments by publishing a new version and notifying Customer, and the new version takes effect on the compliance date of the change in law or thirty (30) days after notice, whichever is later, unless the law requires an earlier date.

14.2 Other updates. Subcontractor may publish a new version of this BAA from time to time. Subcontractor will give Customer at least thirty (30) days' Secure Notice before a new version takes effect, with a summary of the changes and a comparison against the version Customer last accepted. If the new version does not change Sections 2, 4, 5, 7, 10, 11, or 12 and does not reduce Subcontractor's obligations or expand its permitted uses and disclosures of PHI, Customer's continued use of the Services after the stated effective date constitutes acceptance. Any other new version takes effect for Customer only when an authorized representative of Customer accepts it electronically under Section 18, and until then the version Customer last accepted remains in effect.

14.3 Records of versions. Each version of this BAA is identified by a version number and a SHA-256 fingerprint of its published text. The executed copy of each version Customer accepts, with its Execution Record, is retained in Customer's BAA Tracker, and the person who accepted it is emailed a link to it. Customer may provide the executed copy to Upstream Parties to evidence its subcontractor arrangements.

14.4 Negotiated terms. A written amendment signed by both parties, including by electronic signature, prevails over this published text for the parties who signed it.

14.5 Earlier versions. A version of this BAA that Customer accepted before the effective date of this version remains in effect for Customer until Customer accepts this version or the Agreement terminates. Subcontractor will ask Customer to accept this version in the Services at its next sign-in or renewal. In particular, a Customer that accepted Version 2.0 keeps the seventy-two (72) hour reporting periods in Section 5 of Version 2.0 until it accepts this version, and Subcontractor will work to those periods for that Customer until then.

## 15. Notices

15.1 To Customer. Subcontractor gives notices under this BAA by Secure Notice to the Privacy Officer and Security Officer contacts recorded in Customer's organization settings and to the organization account owner. A notice that does not contain PHI (for example a notice of a new version under Section 14) may be given entirely by email. Notice is effective when sent, unless Subcontractor receives an automated delivery failure, in which case Subcontractor will attempt delivery to another administrator on the account. No mailing address is required.

15.2 To Subcontractor. Customer gives notices under this BAA by email to legal@polestargrc.com, and for Security Incidents also through the in-product incident report, with a copy by mail to Polestar GRC, Attn: Jonathan Prine, 434 Kern St, Taft, CA 93268 for notices of breach or termination. Customer will not include PHI in an email notice. Notice is effective when received.

## 16. Miscellaneous

16.1 Regulatory references. A reference to a section of the HIPAA Rules or 42 C.F.R. Part 2 means that section as in effect or as amended.

16.2 Interpretation. Any ambiguity in this BAA will be resolved to permit compliance with the HIPAA Rules. Headings are for convenience only.

16.3 No third-party beneficiaries; confirmation to Upstream Parties. Nothing in this BAA confers any right, remedy, or claim on any person other than the parties, including any Upstream Party, any Client, or any Individual whose PHI is held in the Services. Customer may provide a copy of this BAA to an Upstream Party, but doing so does not make the Upstream Party a party to it. Where an Upstream BAA requires it, Subcontractor will, at Customer's written request, confirm to the named Upstream Party in a short letter that Subcontractor has agreed to the obligations in this BAA with respect to that Upstream Party's PHI; the letter does not amend this BAA or create rights beyond those stated in it.

16.4 Independent contractors. The parties are independent contractors. This BAA does not create a partnership, joint venture, or agency relationship.

16.5 Severability. If any provision of this BAA is held unenforceable, the remaining provisions remain in effect and the unenforceable provision will be modified to the minimum extent needed to make it enforceable and consistent with the HIPAA Rules.

16.6 Entire agreement. This BAA and the Agreement are the entire agreement between the parties about PHI and supersede any prior business associate or subcontractor agreement between them covering the Services.

16.7 Assignment. Neither party may assign this BAA except together with a permitted assignment of the Agreement. Any permitted assignee of Subcontractor must assume this BAA in writing, and Subcontractor will give Customer Secure Notice of the assignment. In addition, Subcontractor may assign this BAA, together with the Agreement, to Polestar GRC, LLC, a limited liability company of which Jonathan Prine is the sole member (the "LLC"), without Customer's consent, on these terms. (a) Subcontractor will give Customer at least thirty (30) days' Secure Notice before the assignment takes effect, stating the LLC's exact legal name, its state of organization and entity number, and the effective date. (b) Before the effective date, the LLC will assume this BAA and the Agreement in a writing signed for the LLC, and will have in place the written agreements Section 4.1 requires with each Downstream Subcontractor. (c) On the effective date, the Services will give Customer an updated executed copy of this BAA naming the LLC. (d) The Services, the locations where PHI is stored and the Downstream Subcontractors will not change because of the assignment. (e) If an Upstream BAA requires Customer to obtain consent to a change of subcontractor and Customer cannot obtain it, Customer may terminate the Agreement and this BAA by written notice before the effective date and receive a refund of prepaid fees for the period after termination. (f) Jonathan Prine remains responsible for obligations that arose before the effective date.

16.8 Electronic records and signatures. The parties agree that this BAA is a written contract for purposes of 45 C.F.R. 164.308(b)(3), 164.314(a)(2)(iii), and 164.504(e)(5), that it may be executed by electronic signature and electronic acceptance under the federal Electronic Signatures in Global and National Commerce Act (15 U.S.C. 7001 et seq.) and the applicable state Uniform Electronic Transactions Act, and that an electronic copy of this BAA with its Execution Record is admissible as an original.

## 17. Execution by Subcontractor

Subcontractor has executed this BAA by the electronic signature of Jonathan Prine, an individual doing business as Polestar GRC, who adopted the typed signature below with the intent to sign each published version of this BAA, including this version. That signature applies to every copy of this version accepted by a customer under Section 18. The published text of this version carries the SHA-256 fingerprint stated in the Execution Record. A countersigned copy of a customer's executed copy is available on request from legal@polestargrc.com.

Polestar GRC, by Jonathan Prine, Owner

Electronically signed on October 9, 2026 for Version 2.2.

## 18. Acceptance by Customer

18.1 How Customer accepts. Customer accepts this BAA when an individual who is an administrator of Customer's organization account, and who is an owner, officer, or employee of Customer or a person Customer has authorized in writing to sign agreements for it, enters Customer's legal name, his or her own name and title, confirms that he or she is authorized to bind Customer, and selects the acceptance control in the Services, in the BAA Tracker or in the dialog the Services show when an upload is blocked under Section 9(d). Acceptance happens only in the Services. No person whose access to Customer's organization account comes through a Polestar partner may accept this BAA for Customer (Section 10.7). No person who works for an organization that referred Customer to Polestar, and not for Customer, may accept this BAA for Customer.

18.2 Execution Record. Subcontractor records the acceptance in an Execution Record that states the legal name of Customer as entered by the person who accepted, Customer's organization account (its name and account number), the person who accepted, that person's title and account email address, the confirmation of authority, the date and time of acceptance (UTC), the network address and browser from which acceptance was made, the method of acceptance (in the Services), the version accepted, and the SHA-256 fingerprint of the published text that was displayed to the person who accepted. The Execution Record is appended to the executed copy, which is retained as a PDF in Customer's BAA Tracker, where Customer's administrators can download it; the person who accepted and the account owner are emailed a link to it, and the email contains no PHI. Customer may request a countersigned PDF of the executed copy from legal@polestargrc.com at any time.

## Signatures

Business Associate (Customer): [CUSTOMER LEGAL NAME]

Accepted electronically as described in Section 18. The Execution Record below forms part of this BAA.

---

Earlier versions of this Subcontractor Business Associate Agreement: [Version 2.1, effective October 8, 2026](https://polestargrc.com/legal/archive/hipaa-subcontractor-baa-v2.1) and [Version 2.0, effective October 1, 2026](https://polestargrc.com/legal/archive/hipaa-subcontractor-baa-v2.0). Every version of our legal documents is listed at [polestargrc.com/legal/archive](https://polestargrc.com/legal/archive).
