Policy
Terms of Service
These terms form a binding agreement between Thotara and the organization that subscribes to the platform, a system of record used by healthcare staffing organizations to manage providers, clients, placements, credentialing, scheduling, travel and billing. They apply to every user who signs in.
Last updated 21 August 2026
1. Agreement and definitions
By signing an order, activating a workspace or using the platform, the subscribing organization ("Customer") accepts these terms. Where a signed master agreement exists between Thotara and Customer, that agreement controls to the extent of any conflict.
- "Service" — the Thotara web application, APIs, portals and related documentation.
- "Workspace" — the isolated tenant environment provisioned for a Customer.
- "Authorised User" — an individual Customer permits to sign in: staff, administrators, provider-portal users and client-portal contacts.
- "Customer Data" — all data, documents and content Customer or its Authorised Users submit to or generate in the Workspace.
- "Order" — the subscription document specifying term, plan, user counts and fees.
2. Accounts, users and administrators
Access is granted per organization. Customer's administrators create accounts, assign roles and permissions, and are responsible for keeping the access list accurate — including prompt removal of leavers. Credentials are personal to each individual and may not be shared, resold or used by more than one person. Customer is responsible for all activity under its Authorised Users' accounts and must notify us promptly of suspected unauthorised access.
Mandatory security settings
Two-step verification is required for every account and cannot be disabled. Staff and administrators must register an authenticator application; provider and client-portal users verify by emailed one-time code. Sessions expire after a period of inactivity. Customer must not circumvent these controls or share authenticator secrets.
Portal users
Customer decides which providers and client contacts receive portal access and is responsible for the accuracy of the records exposed to them. Portal users access the Service under Customer's instructions; their relationship for employment, engagement or payment purposes is with Customer, not with Thotara.
3. Subscription, fees and taxes
- Subscriptions run for the term stated in the Order and renew automatically for successive terms of equal length unless either party gives written notice at least 30 days before the renewal date.
- Fees are invoiced in advance per the Order and are payable within 30 days of the invoice date unless stated otherwise. Fees are non-refundable except as expressly set out in these terms.
- Adding users, workspaces or optional modules mid-term is charged pro rata for the remainder of the term. Reductions take effect at renewal.
- Renewal pricing may change with at least 45 days' written notice before the renewal date.
- Overdue amounts may accrue interest at the lower of 1.5% per month or the maximum permitted by law, and reasonable collection costs may be recovered.
- Fees exclude sales, use, VAT and similar taxes, which are Customer's responsibility except for taxes on Thotara's income.
4. Customer data and ownership
Customer owns and retains all right, title and interest in Customer Data — provider profiles, client and job records, documents, letters, agreements, timesheets and financial records. Customer grants Thotara a limited, non-exclusive licence to host, process, transmit and display Customer Data solely to provide, secure and support the Service, and to comply with law.
- Thotara does not sell Customer Data, does not share it with other customers, and does not use it for advertising.
- Aggregate, de-identified operational statistics may be used to improve reliability and product functionality; these cannot be attributed to Customer or to any individual.
- Customer warrants it has the legal right and, where required, the consents to submit Customer Data, including data about clinicians and facility contacts.
- Customer is responsible for the accuracy of records used for credentialing, payment and contractual decisions.
- Customer may export its data at any time in machine-readable form through the in-app export functions.
5. Acceptable use
Customer and its Authorised Users must not:
- Upload data they have no legal right to process, or patient medical records and protected health information — the Service is not a clinical system of record and must not be used as one.
- Attempt to access another organization's workspace, probe or test tenant isolation, or bypass role, permission or two-step verification controls.
- Reverse engineer, decompile, benchmark for publication, or copy any part of the Service, or build a competing product from it.
- Resell, sublicense, rent or provide the Service to a third party except as a permitted portal user of Customer.
- Introduce malware, run automated scraping or load testing without written consent, or interfere with the integrity or performance of the Service.
- Use the Service in a manner that violates applicable law, including employment, immigration, licensing, export-control and sanctions rules.
- Use AI features to generate deceptive credentials, forged documents or misleading representations about a clinician's qualifications.
Authorised security research is welcome under the coordinated-disclosure process on the security page; it must never involve another organization's live data.
6. AI assistance
The Service uses AI to draft text, extract data from documents, suggest field values from public sources and rank candidate-to-job fit. AI output is a suggestion only: it is queued for human review and is never written to a record, sent to a recipient or signed without a person accepting it.
- Customer is responsible for reviewing AI output before relying on it, and for every credentialing, employment, rate or billing decision it informs.
- AI output may be inaccurate or incomplete; it is not legal, tax, medical, licensing or compliance advice.
- Prompts are limited to the data needed for the requested task and are not used to train third-party foundation models.
- Matching scores rank options for a recruiter. They do not make automated decisions with legal or similarly significant effects about any individual.
- Reasonable usage limits may apply to AI features to protect platform stability; sustained excess use may be metered.
7. Messaging and outreach compliance
Where Customer enables SMS, calling or email features, Customer is the sender and is solely responsible for compliance with the TCPA, CAN-SPAM, state telemarketing rules, carrier policies and equivalent local law. Customer must obtain and evidence any required consent, honour opt-out and unsubscribe requests promptly, respect quiet hours, and only send from numbers and domains it is authorised to use. Recorded calls require all legally necessary notices and consents.
8. Third-party integrations
Optional connectors — telephony, SMS, sourcing and contact enrichment, email delivery and prior-CRM import — run under credentials Customer supplies. Use of those services is governed by Customer's agreement with the relevant vendor. Thotara is not responsible for a third-party service's availability, accuracy, pricing changes, data practices or discontinuation, and a connector may stop working if the vendor changes or withdraws its API. Customer is responsible for the lawfulness of data obtained from sourcing providers.
9. Confidentiality
Each party may receive information the other treats as confidential, including Customer Data, pricing, roadmaps and security documentation. The receiving party will use it only to perform under these terms, protect it with at least reasonable care, and disclose it only to personnel and sub-processors with a need to know who are bound by comparable obligations. These duties continue for three years after the information is received, and indefinitely for Customer Data and trade secrets. Disclosure compelled by law is permitted where the receiving party gives prompt notice, if legally allowed, and limits disclosure to what is required.
10. Data protection
Customer is the controller and Thotara the processor of personal data in the Workspace. Thotara processes personal data only on Customer's documented instructions, assists with data-subject requests, maintains a current sub-processor register with prior notice of changes, imposes confidentiality on personnel, applies the security measures described on the security page, notifies Customer of a personal-data breach without undue delay, and deletes or returns personal data on termination. International transfers rely on Standard Contractual Clauses and the UK Addendum. Full detail, including data categories and retention periods, is in the privacy policy, which forms part of these terms.
11. Security commitments
Thotara will maintain administrative, technical and physical safeguards appropriate to the sensitivity of Customer Data, including tenant isolation enforced at the database layer, least-privilege role-based access, encryption in transit and at rest, mandatory two-step verification, immutable audit logging, enforced retention and secure deletion, and reviewed change control. Safeguards will not be materially degraded during the subscription term. Customer is responsible for its own configuration decisions: role and permission assignments, which records portal users can see, connector credentials, and offboarding of its users.
12. Availability, support and changes
| Commitment | Target |
|---|---|
| Monthly availability target, excluding scheduled maintenance | 99.9% |
| Scheduled maintenance notice for changes affecting sign-in or data access | At least 5 business days where practical |
| Response to a critical outage or confirmed security incident | Within 4 hours |
| Response to a major functional issue | 1 business day |
| Response to a general question or enhancement request | 3 business days |
| Backup frequency and recovery point objective | Daily backups; RPO 24 hours |
Emergency maintenance to address a security threat may be performed without advance notice. The Service is delivered continuously and features evolve; Thotara will not materially reduce core functionality Customer relies on during a paid term without notice and a comparable replacement. Deprecated functionality is announced to administrators at least 60 days before removal.
13. Intellectual property and feedback
Thotara and its licensors own the Service, its software, design, templates, documentation and all improvements. Nothing in these terms transfers that ownership; Customer receives only the limited right to use the Service during the subscription term. Feedback and suggestions may be used without restriction or obligation, and will not include Customer Data. Customer may not use Thotara's trademarks without written permission, and Thotara may reference Customer's name and logo as a customer only with Customer's prior consent.
14. Warranties and disclaimers
Each party warrants it has authority to enter these terms. Thotara warrants that the Service will perform materially as described in its documentation, that it will provide the Service with reasonable skill and care, and that it will not knowingly introduce malicious code. If the Service fails to meet that warranty, Thotara will use reasonable efforts to correct it; if it cannot within a reasonable period, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees — this is Customer's exclusive remedy.
Otherwise the Service is provided "as is". Thotara disclaims all other warranties, including implied warranties of merchantability, fitness for a particular purpose and non-infringement, and does not warrant uninterrupted or error-free operation, the accuracy of AI output or public-source enrichment, or the results of any credentialing, hiring or billing decision. Thotara is not a legal, tax, licensing, medical or compliance advisor, and is not a party to any engagement between Customer, a provider or a facility.
15. Indemnities
Thotara will defend Customer against third-party claims that the Service infringes a patent, copyright, trademark or trade secret, and pay resulting damages and reasonable costs finally awarded or agreed in settlement. Thotara may modify or replace the Service, or terminate the affected subscription with a pro-rata refund, to resolve such a claim. The indemnity excludes claims arising from Customer Data, unauthorised use, or combination with third-party services.
Customer will defend Thotara against third-party claims arising from Customer Data, Customer's outreach and messaging activity, its credentialing or employment decisions, its breach of the acceptable-use section, or its violation of law, and pay resulting damages and reasonable costs. The indemnified party must give prompt notice, allow the indemnifying party to control the defence, and cooperate reasonably; no settlement admitting liability is binding without consent.
16. Limitation of liability
Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill or anticipated savings, even if advised of the possibility. Each party's total aggregate liability arising out of these terms is limited to the fees paid or payable by Customer in the twelve months preceding the event giving rise to the claim.
These limits do not apply to Customer's obligation to pay fees, either party's indemnification obligations, a party's breach of confidentiality, or liability that cannot be limited by law, including fraud, wilful misconduct, death or personal injury caused by negligence.
17. Suspension
Thotara may suspend an account or the Workspace where necessary to stop an active security threat, prevent unlawful activity or a violation of the acceptable-use section, comply with law, or where fees are more than 30 days overdue after written notice. Suspension is limited to what is necessary, notice is given where practical, and access is restored promptly once the cause is resolved.
18. Term, termination and export
Either party may terminate for material breach that remains uncured 30 days after written notice, or immediately if the other becomes insolvent. On expiry or termination, Customer's right to use the Service ends and unpaid fees for the remainder of the committed term become due unless Customer terminated for Thotara's uncured breach.
- Administrators may export Customer Data for 30 days after termination using the in-app export functions.
- After that window the Workspace and its records are deleted according to the retention schedule on the security page; backups roll off within 35 days.
- A written certificate of deletion is available on request.
- Sections on customer data ownership, confidentiality, intellectual property, disclaimers, indemnities, liability, governing law and general terms survive termination.
19. Governing law and disputes
These terms are governed by the laws of the State of Delaware, United States, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods. The parties will first attempt to resolve a dispute through good-faith escalation between senior representatives for 30 days. Unresolved disputes are subject to the exclusive jurisdiction of the state and federal courts located in Delaware, and each party waives any right to a jury trial and to participate in a class action. Either party may seek injunctive relief in any competent court to protect confidential information or intellectual property.
20. General terms
- Changes: material changes to these terms are announced to organization administrators at least 30 days before they take effect; continued use after the effective date constitutes acceptance. For a paid term, changes that materially reduce Customer's rights apply from the next renewal.
- Assignment: neither party may assign these terms without the other's consent, except to a successor in a merger or sale of substantially all assets, with notice.
- Force majeure: neither party is liable for delay caused by events beyond its reasonable control, excluding payment obligations.
- Independent parties: no agency, partnership, joint venture or employment relationship is created.
- Severability and waiver: an unenforceable provision is limited or severed with the remainder intact; a failure to enforce a right is not a waiver of it.
- Notices: notices to Customer go to its administrator email addresses; notices to Thotara go to legal@thotara.com.
- Entire agreement: these terms, the privacy policy, the security page and any Order are the complete agreement and supersede prior discussions; Customer purchase-order terms have no effect.

