1. Acceptance, Scope, and Definitions.
By accessing or using the Benchmark Gensuite Model Context Protocol connector (the “MCP Connector”), you agree to these Terms of Use (this “Agreement”) and our Privacy Policy. If you do not agree, do not use the MCP Connector. The MCP Connector is for business use only. If you act for an organization, you represent that you and your organization have authorized your use.
Your organization’s use of the Benchmark Gensuite platform may also be governed by a subscription, license, or services agreement with us (the “Underlying Agreement,” which includes any applicable Data Processing Agreement or “DPA”). The Underlying Agreement governs any conflict with this Agreement as to the platform and your subscription, and the DPA governs any conflict as to processing of personal information within its scope.
2. Definitions. The following terms apply:
“AI System” – Artificial intelligence models, agents, assistants, applications, and other compatible systems that interact with the platform through the MCP Connector.
“Authorized Purpose” – Your organization’s internal environmental, health and safety, sustainability, quality, operational risk, and compliance management activities, within the scope of its Benchmark Gensuite subscription and enabled application modules.
“MCP Security Incident” – Any actual or reasonably suspected compromise, loss, theft, or unauthorized use, disclosure, or access involving MCP credentials or authorization tokens; AI System or MCP client configurations used to reach the MCP Connector; or data accessed through the MCP Connector.
3. The MCP Connector
The MCP Connector is a standardized interface that uses the Model Context Protocol through which authorized AI Systems interact with the Benchmark Gensuite platform. Subject to the capabilities enabled for your organization and your permissions, an authorized AI System may retrieve operational and governed business data; access records across incidents, inspections, audits, permits, management of change, corrective actions, and other supported applications; update records and initiate approved business processes for an authorized user; execute supported actions; and coordinate multiple platform interactions through supported agentic capabilities. Available functions may change and depend on your subscription, configuration, permissions, enabled MCP tools, and AI System.
4. Access and Use
- (a) Grant. Subject to this Agreement and the Underlying Agreement, we grant you a non-exclusive, non-transferable, non-sublicensable right to use the MCP Connector during the applicable term solely for the Authorized Purpose. Your access and your use, processing, and retention of data retrieved through the MCP Connector must be reasonably necessary for the Authorized Purpose. Access remains subject to the authentication, authorization, permission, governance, and business-rule controls configured for the platform.
- (b) Incorporated Restrictions. The use restrictions in the Underlying Agreement apply in full, including restrictions on copying, modifying, creating derivative works, transferring or sublicensing access, reverse engineering, developing competing products, and removing proprietary notices.
- (c) MCP-Specific Restrictions. You must not, directly or indirectly:
- Circumvent authentication, authorization, access controls, rate limits, safeguards, business rules, or other security or governance controls.
- Scrape, harvest, or otherwise extract data outside the functionality we make available.
- Use the MCP Connector in a manner that is harmful, unlawful, fraudulent, misleading, offensive, or obscene; violates any intellectual property or other right or any law; or violates your organization’s policies.
- Use another person’s credentials, tokens, permissions, or MCP tools without your organization’s authorization.
- Instruct, configure, or permit an AI System to take actions the applicable user or organization is not authorized to take.
- Use the MCP Connector for safety-critical autonomous decision-making, or to take safety-critical actions, without appropriate human oversight, review, and approval.
- Connect an AI System that does not comply with your organization’s acceptable-use and information-security policies or with applicable laws and standards governing AI systems.
- Use AI System interactions to map, reconstruct, derive, or reverse engineer the platform’s business logic, data models, workflow architecture, or other non-public design.
- Store, index, cache, replicate, or otherwise retain data accessed through the MCP Connector outside the platform on a persistent or systematic basis, or maintain a parallel repository or index of platform data, except for transient caching reasonably necessary to complete a user-initiated request, session, or workflow and except for export functionality made available under your subscription.
- Use the MCP Connector to develop, operate, or offer anything that competes with, substitutes for, or replaces the MCP Connector or the platform.
- Use the MCP Connector in connection with content that disparages Benchmark Gensuite, is defamatory, or would reasonably be expected to harm our business, reputation, or goodwill.
- Publish any benchmarking, performance, load, security, or comparative study involving the MCP Connector, the platform, or any AI or agentic capability without our prior written consent.
- (d) Rate Limits. We may set and enforce reasonable rate, throttling, concurrency, or volume limits on AI System interactions, with or without notice, to protect the security, integrity, availability, or performance of the MCP Connector or the platform. We will notify you of material limits where practicable.
- (e) Usage Data. We may monitor use of the MCP Connector and compile aggregated, anonymized statistical and performance data (“Aggregated Statistics”). We own the Aggregated Statistics and may use and publish them, provided they do not identify you or your organization.
5. Credentials
You are responsible and liable for all use of the MCP Connector through your account, credentials, tokens, API credentials, or MCP configuration. Your general obligations to safeguard credentials and configure access permissions are governed by the Underlying Agreement and apply to MCP credentials and tokens. You must promptly revoke access that is no longer needed and promptly notify us of any suspected unauthorized access or compromise.
6. AI Systems and Third Parties
The MCP Connector interoperates with AI Systems and other technology that third parties may provide or operate. Unless we state otherwise, we do not operate or control them, and your use of them may be governed by separate terms with the applicable provider.
7. Customer Responsibility for AI Systems
You are responsible for:
- (a) Ensuring each AI System you connect is approved by your organization and used only by or for authorized users.
- (b) Ensuring only authorized AI Systems and users connect.
- (c) Determining whether a given AI System is appropriate for use with Benchmark Gensuite data, taking into account the sensitivity of the operational, safety, environmental, and compliance data reachable through the MCP Connector.
- (d) Ensuring that data made available to a third-party AI System may lawfully be processed by it.
- (e) All instructions, requests, data, and content transmitted through your account or connection, including anything an AI System generates or initiates.
- (f) We are not responsible for a third-party AI System’s independent collection, storage, retention, processing, disclosure, use, or transmission of information once that information leaves the platform, except as expressly provided in an applicable written agreement.
8. AI Outputs and Actions
AI Systems may misread instructions, generate inaccurate information, select an unintended tool or action, or produce unexpected results. You acknowledge that AI-generated responses and actions may be inaccurate, incomplete, or unsuitable; outputs are not a substitute for professional judgment, regulatory analysis, legal advice, safety decisions, or other required human review; users must review and validate information and actions before relying on them; and actions taken through an AI System may change platform records or start business workflows.
- (a) Genny AI MCP Agent. If enabled for your organization, the Genny AI MCP Agent may interpret user intent, resolve ambiguity, select and sequence tools, and orchestrate multi-step workflows. Its interpretation of intent and resolution of ambiguity may be wrong and may produce unintended requests, outputs, record changes, notifications, or actions.
- (b) Human Oversight. You must configure and maintain appropriate approval processes, role-based permissions, and human review checkpoints for AI System and Genny AI actions involving high-risk operations, including changes to safety records, compliance workflows, and permit statuses, and any action that could materially affect safety, compliance, legal, or operational outcomes. You are responsible for the consequences of a cascading error in a multi-step workflow to the extent it results from your failure to implement or maintain that oversight.
- (c) Provenance. You must ensure your AI Systems, MCP clients, and any interface presenting MCP Connector data clearly identify data retrieved from the platform as platform data, and clearly distinguish platform records from AI-generated interpretations, summaries, recommendations, and inferences. You must not present AI-generated content in a way that could reasonably suggest it is a platform record or a Benchmark Gensuite determination, and you must not use our names, logos, or marks, or make any statement suggesting we developed, endorsed, reviewed, certified, or approved your AI System or its outputs, without our prior written consent.
9. Data, Security, and Legal Process
- (a) Ownership. The Underlying Agreement governs ownership of data your organization provides, under which you retain all right, title, and interest in it. You also own AI-generated outputs derived from your data, except for the MCP Connector, the platform, the Aggregated Statistics, and our underlying intellectual property. Where an output reflects our intellectual property, your rights in it remain subject to Section 11.
- (b) Processing Framework. The MCP Connector processes information within the platform’s security, governance, authorization, and business-rule framework. Where a DPA applies, it governs processing of personal information within its scope and prevails over this Agreement on that subject. Your use is also subject to our Privacy Policy.
- (c) Our Model Training Commitment. We will not use data accessed through the MCP Connector to train, fine-tune, or improve any AI or machine learning model without your organization’s prior written consent. We will otherwise use that data only to provide, secure, maintain, support, and improve the MCP Connector, to comply with law, or as the Underlying Agreement and DPA permit.
- (d) Your Model Training Obligation. You must not use, and must ensure that no AI System, MCP client, model or agent provider, or other tool that receives data through the MCP Connector uses, that data to train, fine-tune, retrain, ground, embed, index for model retrieval, or otherwise develop or improve any AI or machine learning model, product, or service, without our prior written consent and your organization’s prior written consent. You must obtain and maintain contractual terms with each such provider sufficient to give effect to this restriction, and must notify us promptly if you learn of a violation. A violation of this Section 9(d) is a material breach and is subject to your indemnity in Section 13.
- (e) AI System Security Controls. You must ensure each AI System, MCP client, and third-party model provider that connects to or receives data through the MCP Connector maintains industry-standard security controls appropriate to the data, including strong authentication, encryption in transit and at rest, least-privilege access, access logging and monitoring, and incident response. Each third-party model provider must meet data protection and security standards reasonably consistent with those set forth in the Underlying Agreement.
- (f) Protocol Security. You must ensure each MCP client and AI System you connect complies with the applicable Model Context Protocol specification’s security requirements and OAuth security best practices, including validating that tokens presented to the MCP Connector were issued for it, not passing tokens through, and obtaining user consent for each client acting on a user’s behalf. You must not deploy any proxy, gateway, or intermediary configuration that circumvents per-client authorization, consent, or audience validation, or that lets an AI System exceed the scope authorized for the applicable user.
- (g) MCP Security Incidents. You must notify us of an MCP Security Incident without undue delay and no later than seventy-two (72) hours after becoming aware of it, and must provide the information reasonably available about its nature, scope, and likely consequences, along with reasonable cooperation to investigate, contain, and remediate it. Where an MCP Security Incident involves personal information within the DPA’s scope, the DPA’s notification and remediation procedures also apply and prevail on that subject.
- (h) Cross-Border Transfers. You must ensure data accessed through the MCP Connector is not transferred, copied, or made available to any jurisdiction, recipient, AI System, or service in a way that conflicts with applicable data protection laws, the Underlying Agreement, or any required transfer mechanism, and must configure your AI Systems and providers accordingly.
- (i) Legal Process. We may access, preserve, and disclose MCP Connector data and metadata, including query logs, tool invocation and agent activity records, credential and authentication records, and configuration records, where we reasonably believe applicable law or a valid subpoena, court order, warrant, regulatory demand, or similar process (“Legal Process”) requires it. Unless prohibited, we will use commercially reasonable efforts to give you notice sufficient to seek a protective order. Where the Legal Process implicates personal information within a DPA scope, the DPA’s procedures govern and prevail on that subject, including our obligations to notify you, redirect the authority to you where practicable, oppose the demand where appropriate, and withhold disclosure absent a definitive judicial decision or order. We are not liable for losses arising from our good-faith compliance with valid Legal Process under this Section.
10. Confidentiality
The confidentiality provisions of the Underlying Agreement govern confidential information exchanged in connection with the MCP Connector and apply to both parties. If no Underlying Agreement applies, you must protect our non-public business, technical, security, and proprietary information with at least reasonable care and must not disclose or use it except as needed to use the MCP Connector under this Agreement.
11. Intellectual Property
The Underlying Agreement governs ownership of the MCP Connector, the platform, and related materials. We and our licensors retain all right, title, and interest in our proprietary data structures, schemas, taxonomies, algorithms, models, business logic, workflows, configuration methods, and workflow architecture exposed through the MCP Connector, and in all improvements and derivative works of them. No rights are granted except as this Agreement or another written agreement expressly provides. We may use any feedback you give us about the MCP Connector without restriction or obligation. Feedback is non-confidential unless we agree otherwise in writing.
12. Warranties and Disclaimer
You represent and warrant that you have all rights, permissions, authorizations, and consents necessary for the data and instructions you submit through the MCP Connector and for the AI Systems you authorize to access it. THE WARRANTY DISCLAIMERS IN THE UNDERLYING AGREEMENT APPLY IN FULL TO THE MCP CONNECTOR. WE DO NOT WARRANT THAT THE MCP CONNECTOR OR ANY OUTPUT, RESULT, AI-GENERATED RESPONSE, OR ACTION WILL BE ACCURATE, COMPLETE, ERROR-FREE, UNINTERRUPTED, SECURE, OR SUITABLE FOR ANY PARTICULAR PURPOSE, OR THAT THE MCP CONNECTOR WILL BE COMPATIBLE WITH EVERY AI SYSTEM, MODEL, AGENT, MCP CLIENT, OR THIRD-PARTY SERVICE. AI-GENERATED OUTPUTS ARE NOT GUARANTEED TO BE ACCURATE, COMPLETE, OR SUITABLE FOR REGULATORY COMPLIANCE, SAFETY DETERMINATIONS, OR LEGAL PURPOSES AND MUST NOT BE RELIED ON WITHOUT INDEPENDENT HUMAN VERIFICATION.
13. Indemnification
The indemnification obligations in the Underlying Agreement apply in full. In addition, you will indemnify, hold harmless, and at our option defend Benchmark Gensuite and our officers, directors, employees, agents, affiliates, successors, and assigns against losses from third-party claims relating to:
- (a) Your connection or authorization of an AI System in violation of applicable law or your organization’s policies or permissions.
- (b) AI-generated content or outputs transmitted through your account or AI System that infringe or misappropriate a third party’s intellectual property rights.
- (c) Your failure to implement or maintain the human oversight, approval processes, permissions, or review checkpoints required by Section 8(b).
- (d) Any AI System’s interaction with or reliance on data obtained through the MCP Connector, including resulting regulatory penalties or fines, to the extent applicable law permits.
- (e) Your breach of Section 7(d).
The Underlying Agreement governs the indemnification procedure, including notice, control of defense, cooperation, and participation. You may not settle any claim in a way that imposes liability or obligations on us without our prior written consent.
14. Limitation of Liability
The exclusions of consequential, incidental, indirect, exemplary, special, enhanced, and punitive damages, and of lost profits, revenue, goodwill, and data and costs of replacement goods or services, in the Underlying Agreement apply in full to this Agreement. WE ARE NOT LIABLE FOR ERRORS, OMISSIONS, OR HARMFUL OUTPUTS GENERATED BY THIRD-PARTY AI MODELS, AGENTS, MCP CLIENTS, OR OTHER THIRD-PARTY SYSTEMS INTERACTING THROUGH THE MCP CONNECTOR, EXCEPT WHERE THAT LIABILITY CANNOT BE DISCLAIMED UNDER APPLICABLE LAW OR THE UNDERLYING AGREEMENT EXPRESSLY PROVIDES OTHERWISE. EXCEPT AS PROHIBITED BY LAW OR EXPRESSLY PROVIDED IN THE UNDERLYING AGREEMENT, OUR AGGREGATE LIABILITY FOR CLAIMS ARISING OUT OF OR RELATING TO THE MCP CONNECTOR OR THIS AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID TO US FOR THE MCP CONNECTOR DURING THE ONE (1) MONTH BEFORE THE EVENT GIVING RISE TO THE CLAIM. THIS IS A SEPARATE, LOWER CAP THAT DOES NOT INCREASE, SUPPLEMENT, OR RESET THE AGGREGATE CAP IN THE UNDERLYING AGREEMENT, AND RECOVERY UNDER THIS AGREEMENT AND THE UNDERLYING AGREEMENT DOES NOT STACK.
15. Term, Suspension, and Termination
This Agreement begins when you first use the MCP Connector and continues while you are authorized to use it, subject to the Underlying Agreement.
- (a) Termination. The Underlying Agreement governs general termination rights and cure periods. We may also terminate or suspend your MCP Connector access for any breach of this Agreement.
- (b) Suspension. We may suspend access to all or part of the MCP Connector if we reasonably determine that there is a threat or attack involving the MCP Connector or our systems; that use creates a security, privacy, operational, or integrity risk; that use is fraudulent or unlawful; that applicable law prohibits providing the MCP Connector; that use materially violates this Agreement; that an AI System, MCP client, third-party provider, or other dependency has become unavailable; that an MCP Security Incident has occurred or is reasonably suspected; that an AI System or MCP client does not comply with Section 7(e); or that suspension is otherwise reasonably necessary to protect us, our subscribers, users, vendors, systems, or data. Where practicable, we will use commercially reasonable efforts to give notice and to restore access once the issue is resolved.
- (c) Effect of Termination. On expiration or termination of MCP Connector access, you must immediately stop all AI System access, stop using our intellectual property except as another agreement authorizes, purge all cached, copied, or extracted data obtained through the MCP Connector from your AI Systems, MCP clients, and providers under your control except where law requires retention, and certify that purge to us in writing within thirty (30) days.
- (d) Relationship to Underlying Agreement. Suspending or terminating MCP Connector access does not terminate the Underlying Agreement. Expiration or termination of the Underlying Agreement automatically terminates MCP Connector access. Data retention and deletion otherwise follow the applicable agreements, retention policies, and legal requirements.
16. Beta and Pre-Release
If we identify the MCP Connector or any functionality as beta, preview, early access, pre-release, or evaluation, it is experimental and may contain errors, be interrupted, change materially, or be discontinued before general availability. Beta functionality is provided “as is” and “as available,” without warranty of any kind, express, implied, or statutory, including warranties of merchantability, fitness for a particular purpose, accuracy, reliability, title, and non-infringement. Beta functionality is for evaluation and feedback only. You assume all risk of using it and must not rely on it for production-critical, safety-critical, regulatory, or other consequential activities unless we expressly authorize that in writing. We may modify, limit, suspend, or discontinue beta functionality at any time. When we release generally available functionality, the terms for that functionality supersede this Section 16. Participating in a beta does not guarantee access to, availability of, or any particular features, service levels, or pricing for the generally available version.
We may use any feedback on beta functionality without restriction or compensation, subject to any confidentiality obligations covering your confidential information.
17. Compliance and Regulatory Cooperation
Your use of the MCP Connector, your AI Systems, and the data you access must comply with all applicable laws, regulations, regulatory guidance, and industry standards, including those governing AI systems, automated decision-making, privacy, cybersecurity, recordkeeping, safety, and environmental, health, and safety matters. We may modify the MCP Connector, its functionality, or this Agreement as reasonably necessary to comply with new or changed laws, regulations, regulatory guidance, or AI governance frameworks. We will give notice of material changes where practicable. You must reasonably cooperate with us in responding to regulatory inquiries, audits, investigations, or information requests concerning AI System activity on the platform, including by providing information, records, and personnel, subject to applicable confidentiality and legal restrictions.
- (a) Transparency. You must tell your end users and other affected stakeholders that AI Systems are interacting with the platform through the MCP Connector where applicable law, regulation, or regulatory guidance requires it, and must obtain any required consents, notices, or approvals.
- (b) Compliance Verification. On reasonable written notice, and no more than once a year unless we reasonably suspect a material breach or an MCP Security Incident, you must give us documentation sufficient to verify your compliance with this Agreement, including the AI Systems, MCP clients, and model providers connected to the MCP Connector, the security controls applying to them, and your compliance with Sections 4(c), 7(d), 7(e), and 7(f). Documentation review satisfies this obligation in the first instance, including certifications, audit reports, penetration test summaries, configuration records, and access logs; deeper inspection or technical audit is a last resort where the documentation is insufficient to address our inquiry. Each party bears its own costs of a documentation review. If a review or audit reveals a material breach, you bear its reasonable costs; otherwise we do. Verification occurs during normal business hours, will not unreasonably interfere with your operations, and is subject to applicable confidentiality obligations.
18. General
- (a) Governing Law. Ohio law governs this Agreement, without regard to conflict of law rules.
- (b) Forum. Any suit, action, or proceeding arising out of or relating to this Agreement must be brought exclusively in the Ohio state courts located in Hamilton County, Ohio or in the United States District Court for the Southern District of Ohio. Each party submits to the personal jurisdiction of those courts and waives any objection based on venue or inconvenient forum.
- (c) Export. The MCP Connector may use technology subject to U.S. export control laws. You must comply with applicable export control and sanctions laws and must not make the MCP Connector available where doing so is prohibited.
- (d) U.S. Government End Users. The MCP Connector and related software and documentation are commercial computer software and commercial computer software documentation under FAR 12.212 and DFARS 227.7202. If you are or are acquiring on behalf of a U.S. Government agency or entity, the Government’s rights are governed solely by this Agreement and the Underlying Agreement and are restricted under FAR 12.212 and DFARS 227.7202. No other rights are granted.
- (e) Modifications. We may modify this Agreement. Modified terms take effect when posted or on any later stated effective date, and we will give additional notice of material modifications where appropriate. Continued use after modified terms take effect constitutes acceptance.
- (f) Integration. Subject to the Underlying Agreement, this Agreement is the entire agreement on use of the MCP Connector and supersedes prior representations on that subject.
- (g) Other General Terms. The Underlying Agreement’s provisions on severability, waiver, assignment, relationship of the parties, headings, and survival apply to this Agreement. If no Underlying Agreement applies: any invalid or unenforceable provision will be modified to the minimum extent necessary and the rest remains in effect; our failure to enforce a provision does not waive it; you may not assign this Agreement without our prior written consent, while we may assign it or delegate our obligations as law permits; and the provisions on intellectual property, confidentiality, disclaimers, indemnification, limitation of liability, compliance, and governing law survive.
19. Contact and Notices
For questions about this Agreement, contact Benchmark Gensuite at [email protected]. Send notices to [email protected] or to 5181 Natorp Blvd., Suite 610, Mason, Ohio 45040, in person, by email, by certified or registered mail with return receipt requested, or by recognized overnight courier. Notices are effective on our receipt. You consent to receiving electronic communications from us about the MCP Connector, and agree that notices, agreements, and disclosures we send electronically satisfy any requirement that they be in writing.