MIQ Source Access Agreement
| Field | Value |
|---|---|
| Document ID | MIQ-SOURCE-ACCESS-001 |
| Version | 2026-09-02 (published version; instrument form 1.1 source-access form) |
| Date | 2026-07-16 |
| Provider | Mechanus IQ Ltd. |
| Client | [Client legal name] |
| Effective date | [Date] |
No statement in this Agreement represents outside legal, tax, accounting, insurance, lender, regulator, privacy review, DMS-vendor, or professional approval.
This Source Access Agreement is entered into by Mechanus IQ Ltd. ("MIQ" or "Provider") and the client named above ("Client"). It authorizes a limited, documented path for Client-approved, PII-stripped operational exports to be provided to MIQ only under the complete paid-service or no-fee diagnostic instrument stack stated in Section 1.3.
1. Purpose And Agreement Stack
1.1 Purpose. This Agreement governs Client's authorization for MIQ to request, receive, validate, and use approved operational exports from Client-approved source systems for MIQ's forensic operational intelligence services.
1.2 No broad access grant. This Agreement does not give MIQ general access to Client systems, live DMS access, administrator access, credentialed access, lender portal access, OEM portal access, email access, finance portal access, payment system access, formal API access, production integration access, or any other account access.
1.3 Required service stack. For paid Services, MIQ will not receive or process Client Data until the parties have executed the Master Services Agreement, Data Processing Agreement, Statement of Work, and this Source Access Request Agreement. For a no-fee diagnostic, MIQ will not receive or process Client Data until the parties have executed the Diagnostic Engagement Letter, Data Processing Agreement, and this Source Access Request Agreement. A Pilot Agreement is supplemental and does not by itself authorize source access or replace any required instrument.
1.4 DPA control. The Data Processing Agreement controls privacy, security, retention, subprocessors, model inference, cross-border transfer, Client Data, aggregate use, controlled learning, data-subject requests, audit, return, export, and offboarding. If this Agreement conflicts with the DPA on those subjects, the DPA controls unless a later signed instrument expressly amends the DPA and is at least as protective.
1.5 SOW and service-scope control. The applicable statement of work, pilot schedule, order form, or diagnostic engagement letter controls service scope, deliverables, fees, timelines, Authorized Recipients, and selected modules. This Agreement controls only the source-access and export-authorization mechanics.
1.6 No implied model, aggregate, or learning right. This Agreement does not authorize model-assisted inference, public AI tool upload, model training, cross-client benchmarking, aggregate anomaly intelligence, controlled learning, federated learning, affiliate transfer, or contribution of client-derived data to Singularity or any other affiliate.
2. Definitions
2.1 Approved Export means a Client-approved operational export listed in Schedule A or later approved in writing by both parties for the relevant service purpose.
2.2 Approved Transfer Channel means SFTP or another mutually approved secure transfer method listed in Schedule A. Ordinary email, consumer messaging tools, uncontrolled public links, shared personal drives, and other uncontrolled transfer paths are not Approved Transfer Channels.
2.3 Authorized Client Source means a DMS, accounting system, CRM, service system, warranty system, inventory system, lender report, OEM report, spreadsheet, or other Client-controlled source listed in Schedule A.
2.4 Client Data has the meaning given in the DPA.
2.5 Credentials means usernames, passwords, API secrets, tokens, session cookies, MFA codes, service-account credentials, SSH keys, private keys, or other account-access material.
2.6 Operational Data means PII-stripped dealership data such as dollar amounts, dates, categorical codes, counts, ratios, product categories, lender codes, department codes, stock numbers, deal numbers, repair order numbers, postal forward sortation area where approved, and Client-assigned staff codes or other pseudonymous identifiers approved in writing.
2.7 PII Strip Confirmation means Client's written confirmation, transfer manifest, stripper run summary, or equivalent record confirming that customer personal information, prohibited employee personal information, Credentials, full VINs, short VINs, last-eight VINs, raw partial VINs, raw VIN hashes, account numbers, code-to-person maps, free-text PII, and other excluded fields have been removed before transfer.
2.8 Source Access Request means MIQ's written request for one or more Approved Exports from one or more Authorized Client Sources.
2.9 Transfer Manifest means the transfer record described in Schedule B.
2.10 Capitalized terms used but not defined in this Agreement have the meanings given in the Master Services Agreement, the Data Processing Agreement, or the Diagnostic Engagement Letter, as applicable. MIQ and Client are each a "Party" and together the "Parties."
3. Client Authority And Approval
3.1 Client authority. Client represents that it has authority to approve each Authorized Client Source, Approved Export, Approved Transfer Channel, and service purpose listed in Schedule A.
3.2 Internal approvals. Client is responsible for obtaining any internal owner, board, manager, privacy, security, employee, union, lender, OEM, DMS-vendor, regulator, customer, professional-advisor, or contractual approval required before exporting data or authorizing MIQ to use it.
3.3 No third-party authority by implication. This Agreement does not imply that any lender, OEM, insurer, DMS vendor, payment processor, customer, employee, regulator, or other third party has authorized access, export, use, disclosure, or reliance.
3.4 Authorized contacts. Only the Client contacts listed in Schedule A may approve Source Access Requests, transfer manifests, replacement exports, scope changes, and source-access termination notices.
3.5 Client source accuracy. Client remains responsible for the accuracy, completeness, and lawful preparation of Approved Exports. MIQ may identify data-quality issues but does not certify Client's source systems.
4. Source Access Scope
4.1 Limited to Schedule A. MIQ may request and receive only the Authorized Client Sources, export families, date ranges, rooftops, legal entities, transfer channels, recipients, and special exclusions listed in Schedule A or later approved in writing by both parties.
4.2 Minimum necessary data. Client will provide only the minimum Operational Data necessary for the approved service purpose.
4.3 No live system access by default. Live system access is excluded. A formal API or production integration path can be activated only by a separate signed integration schedule, SOW, order form, and DPA language that identifies the source system, field scope, credential or token model, logging limits, access owner, revocation path, and security responsibilities. Schedule A may reference that separately authorized path, but Schedule A cannot create it by itself.
4.4 No unstructured upload by default. PDF, image, scanned, and free-text exports are not upload-approved unless a later written instrument and acceptance harness authorize the specific template, PII suppression, column alignment, and structured-gate behavior.
4.5 No customer PII. Client must remove customer personal information before transfer, including customer names, addresses, telephone numbers, email addresses, Social Insurance Numbers, driver's licence numbers, other government-issued identifiers, customer financial account numbers, credit bureau information, bank account data, payment card data, dates of birth, and comparable direct identifiers.
4.6 VIN and account-number controls. Full VINs, short VINs, last-eight VINs, raw partial VINs, raw VIN hashes, customer account numbers, bank account numbers, payment-card numbers, lender-account numbers, trust-account numbers, and comparable trace-back identifiers are excluded. Any future exception requires explicit founder-approved constitutional authority plus a separate signed DPA and handling instrument stating the field scope, purpose, minimization, retention, masking, access, and approval controls. Schedule A cannot create that exception by itself.
4.7 Staff-code controls. Staff fields are dropped by default. Staff-code mode may be used only if Schedule A expressly allows it for the relevant workflow. Client must not provide the code-to-person map to MIQ. Any future exception requires explicit founder-approved constitutional authority plus a separate signed DPA and handling instrument stating the purpose, minimization, retention, access, and approval controls.
4.8 Free-text controls. Free-text notes, comments, message bodies, scanned document text, complaint narratives, email bodies, chat logs, and comparable narrative fields are excluded unless a later written instrument expressly approves a specific minimized field and review process.
5. Prohibited Access Methods
5.1 No Credentials. Client must not provide Credentials to MIQ. MIQ will not ask for, receive, store, use, share, or test Credentials under this Agreement.
5.2 No scraping or automation workaround. This Agreement does not authorize scraping, screen scraping, robotic process automation, stealth browser automation, session replay, browser extension collection, virtual-machine-per-dealership workarounds, shadow accounts, shared accounts, credential pooling, or unauthorized access.
5.3 No passive monitoring. MIQ will not place passive monitoring tools, third-party analytics, session recording, behavioral telemetry, tracking pixels, advertising pixels, fingerprinting, or surveillance tools on Client systems.
5.4 No public AI upload. MIQ will not place Client Data into public AI chat tools, general-purpose developer assistants, model-training pipelines, or unauthorized developer tools.
5.5 No personal-device storage. MIQ will not intentionally store Client Data on unmanaged personal devices.
6. Transfer Method And Manifest
6.1 Default transfer. The default Approved Transfer Channel is SFTP or another mutually approved secure transfer method listed in Schedule A.
6.2 Transfer Manifest required. Each transfer must include, before or with the transfer, a Transfer Manifest or equivalent written record identifying the file names, export family, source system, date range, row count where available, PII Strip Confirmation, transfer channel, transfer date, Client approver, and MIQ recipient.
6.3 Encrypted package fallback. A one-time encrypted package may be used only through an Approved Transfer Channel, only if both parties approve that method in writing for the specific transfer, only if the password or key is sent through a separate approved channel, and only if the files are PII-stripped before transfer.
6.4 No ordinary email transfer. Client must not send exports by ordinary email, consumer messaging tools, uncontrolled public links, shared personal drives, uncontrolled portal links, or any public AI tool.
6.5 Replacement exports. If an export is incomplete, corrupted, out of scope, unsafe, or not PII-stripped, MIQ may request a replacement export and may stop processing until replacement is complete.
7. PII Strip Confirmation And Safety Stop
7.1 Client confirmation. Client must provide a PII Strip Confirmation for each Approved Export before MIQ accepts, stores, normalizes, analyzes, or relies on the export, except for the limited handling needed to reject, quarantine, return, or delete an unsafe transfer.
7.2 Dealer-side stripping. Where Client uses a dealer-side stripping tool or workflow, Client should provide the relevant run summary or equivalent result showing whether the output is upload-allowed.
7.3 Upload-allowed rule. MIQ may reject any file that is not marked upload-allowed, is marked review-required, is quarantine-only, is blocked as unstructured, or lacks equivalent written approval.
7.4 Safety stop. If MIQ reasonably believes an export contains customer PII, unnecessary employee PII, Credentials, full VINs, short VINs, last-eight VINs, raw partial VINs, raw VIN hashes, account numbers, code-to-person maps, free-text PII, unsafe data, or data outside the agreed scope, MIQ may reject, quarantine, delete, return, suspend processing, or request a replacement export.
7.5 Notice of unsafe data. MIQ will notify Client's designated contact when MIQ rejects, quarantines, deletes, returns, or suspends processing for an unsafe export, unless notice is legally restricted.
7.6 Independent MIQ intake screening. MIQ operates an independent intake screen that checks each export and rejects detectable customer personal information fail-closed before the export is accepted into storage. Personal information identified at intake is not retained. This screening is a second protective layer: it supplements, and does not replace or transfer to MIQ, Client's stripping and confirmation obligations under this Agreement, and it is not a certification that an export is free of personal information.
8. MIQ Use And Handling Obligations
8.1 Use limit. MIQ may use Approved Exports only for the service purpose stated in the complete paid-service or no-fee diagnostic instrument stack described in Section 1.3.
8.2 Confidential treatment. MIQ will treat Approved Exports and related manifests as Client Confidential Information under the applicable service agreement.
8.3 Access limitation. MIQ will limit access to Approved Exports to personnel, contractors, and service providers who need access for the approved service purpose and are subject to confidentiality and security obligations.
8.4 Audit metadata. MIQ may keep minimal audit metadata, transfer records, validation results, rejection records, and evidence records consistent with the DPA and applicable service instrument. Audit metadata must exclude raw customer PII, prohibited field values, Credentials, payload rows, free-text contents, and source-file contents.
8.5 No paid engagement or retired economics by implication. A Source Access Request does not create a paid service, production dashboard deployment, evidence-rail activation, model-inference election, aggregate-intelligence activation, or controlled-learning authorization; any such current capability requires its own applicable signed authority. The former Founding Dealer Network, performance-fee, Recovery Credit Bank, Strategic Dealer Note, and network-pool constructs are retired, create no current authority, and cannot be activated by this request or any other client instrument.
9. Model, Aggregate, And Evidence Boundaries
9.1 Model inference excluded by default. Model-assisted inference over Client Data is excluded unless the DPA, SOW, order form, processing schedule, or later written instruction expressly authorizes it.
9.2 No training by access. Source access, transfer, account setup, upload attestation, or continued use does not authorize model training, fine-tuning, tuning, calibration, feature selection, model evaluation, benchmarking, model improvement, controlled learning, federated learning, or contribution of model updates.
9.3 No aggregate right by access. Source access does not authorize cross-client benchmarking, aggregate anomaly intelligence, commercial aggregate products, lender-facing products, OEM-facing products, insurer-facing products, investor-facing products, public aggregate disclosure, or affiliate transfer.
9.4 Evidence records. MIQ may preserve transfer manifests, source-row references, validation outputs, rejection records, hash-only integrity records, and method notes only as authorized by the DPA, SOW, evidence schedule, or applicable service instrument.
9.5 No legal-status guarantee. Evidence records support provenance, sequencing, auditability, and quality control. A cryptographic integrity record proves only that the referenced record existed in its exact form at the stated time. MIQ does not represent any evidence record as court-admissible, regulator-approved, or legally sufficient, and no MIQ statement, schedule, or artifact positions an evidence record in those terms.
10. Termination Of Source Access
10.1 End of authorization. Authorization under this Agreement ends on the earliest of:
- completion of the Source Access Request;
- termination or expiry of the applicable service instrument;
- termination or expiry of the DPA where Client Data is involved;
- Client's written withdrawal of source-access authorization;
- MIQ's written termination of the unsafe or unauthorized source-access path; or
- any date listed in Schedule A.
10.2 Immediate suspension. MIQ may suspend source access immediately if Client provides unsafe data, attempts to provide Credentials, requests scraping or unauthorized access, refuses to provide PII Strip Confirmation, materially changes the source scope without written approval, or creates a legal, privacy, security, ethical, or reputational risk for MIQ.
10.3 No continuing access. Unless a later written instrument expressly authorizes a formal integration path, MIQ has no continuing access to Client systems after each Approved Export transfer is complete.
10.4 Offboarding. Return, export, retention, destruction, deletion confirmation, backup expiry, legal hold, and evidence-record treatment follow the DPA and applicable service instrument.
11. Reliance And Client Decisions
11.1 No professional advice. MIQ does not provide legal, tax, accounting, audit, insurance, investment, employment, lending, regulator, OEM, DMS-vendor, or compliance-certification advice.
11.2 No third-party reliance. No lender, OEM, insurer, DMS vendor, regulator, employee, customer, counterparty, purchaser, investor, or other third party may rely on a Source Access Request, Transfer Manifest, PII Strip Confirmation, MIQ validation result, or MIQ output unless MIQ signs a separate reliance letter.
11.3 No sole reliance. Client must not use MIQ outputs as the sole basis for employment discipline, termination, customer action, lender disclosure, insurer disclosure, OEM escalation, regulator disclosure, public accusation, chargeback demand, clawback demand, litigation position, or comparable high-impact action.
11.4 Client approvals remain Client's responsibility. Client remains responsible for deciding whether the export, service purpose, use, disclosure, reliance, and follow-on action are lawful and appropriate for Client.
12. General Terms
12.1 Independent contractor. MIQ is an independent contractor and is not Client's employee, agent, fiduciary, auditor, legal advisor, tax advisor, accountant, insurance advisor, lender representative, OEM representative, DMS-vendor representative, regulator representative, or compliance officer.
12.2 Amendments. This Agreement may be amended only by a written instrument signed or otherwise accepted by both parties.
12.3 Governing law. This Agreement is governed by the laws of the Province in which the Client's principal place of business is located and the federal laws of Canada applicable therein.
12.4 Counterparts and electronic signatures. This Agreement may be signed electronically and in counterparts.
12.5 English language. The Parties expressly request that this Agreement and all related documents be drawn up in English.
12.6 Survival. Confidentiality, prohibited-use, no-credential, no-scraping, no-public-AI, data-handling, evidence, reliance, offboarding, and audit-record provisions survive expiry or termination to the extent applicable. Any surviving liability or other risk-allocation provisions are those in the governing Master Services Agreement, Pilot Agreement, or Diagnostic Engagement Letter, as applicable.
13. Signatures
Accepted and agreed:
| Mechanus IQ Ltd. | [Client legal name] |
|---|---|
| Signature: ______ | Signature: ______ |
| Name: Bowen Schreyer | Name: ______ |
| Title: Founder & Chief Architect, Co-CEO | Title: ______ |
| Date: ______ | Date: ______ |
Schedule A: Source Access Request
Complete every row marked "Required" before MIQ requests, accepts, stores, normalizes, analyzes, or relies on a client-specific export, except for limited quarantine, rejection, return, or deletion handling.
| Item | Required | Entry or default |
|---|---|---|
| Client legal name | Yes | [Client legal name] |
| Scoped rooftop(s) or business unit(s) | Yes | [Legal name, store name, rooftop ID, or business unit] |
| Scoped legal entities | Yes | [Legal entity name(s)] |
| Excluded rooftops, entities, departments, or date periods | Yes | [List exclusions, or state "none"] |
| Governing service instrument | Yes | [Paid path: executed MSA plus SOW / no-fee path: executed Diagnostic Engagement Letter] |
| DPA reference | Yes | [DPA title, date, version, and signature or acceptance status] |
| SOW, order form, or diagnostic reference | Yes | [Executed SOW number for paid Services / executed Diagnostic Engagement Letter reference for no-fee diagnostic] |
| Service purpose | Yes | [Specific diagnostic, pilot, monitoring, recovery, or control-support purpose] |
| Authorized Client source system(s) | Yes | [DMS / accounting / CRM / service / warranty / inventory / lender report / OEM report / spreadsheet / other] |
| Source-system platform and version, if known | Yes | [CDK / PBS / Quorum / Reynolds / DealerTrack / QuickBooks / Sage / Xero / other / unknown] |
| Approved export family or families | Yes | [deal_log / funding_report / fi_product_report / aging_report / reserve_statement / service_ro / parts_inventory / financial_statement / lender_decision_log / other written family] |
| Date range | Yes | [Start date to end date, or current snapshot date] |
| Minimum field scope | Yes | [Only fields necessary for the approved service purpose and allowed by Schedule C] |
| Approved Transfer Channel | Yes | SFTP or another mutually approved secure transfer method only. No ordinary email, consumer messaging, uncontrolled public link, shared personal drive, credential handoff, public AI upload, or uncontrolled portal link. |
| Transfer Manifest | Yes | Required for every file or export package before or with transfer. Use Schedule B or an equivalent written record. |
| PII Strip Confirmation | Yes | Required for every export before acceptance, storage, normalization, analysis, or reliance, except limited quarantine, rejection, return, or deletion handling. |
| PII stripping method | Yes | [Dealer-side MIQ stripper / Client internal stripping workflow / other written method] |
| Upload-allowed evidence | Yes | Default: run_summary.upload_allowed: true from the dealer-side stripper, or an equivalent written PII Strip Confirmation approved by MIQ. structured_review_required, quarantine_only, blocked_unstructured, missing evidence, or unclear evidence is not upload-approved. |
| Staff-code treatment | Yes | Default: drop staff fields. Code mode is approved only if this row expressly says "code mode approved for this workflow" and the DPA or SOW allows it. |
| Code-to-person map | Yes | Default: retained by Client and not transferred to MIQ. Any future exception requires explicit founder-approved constitutional authority plus a separate signed DPA and handling instrument. |
| Full VIN, short VIN, last-eight VIN, raw partial VIN, raw VIN hash, account-number, credential, code-to-person map, and free-text treatment | Yes | Default: excluded. Any future exception requires explicit founder-approved constitutional authority plus a separate signed DPA and handling instrument that names the field, purpose, minimization, retention, masking, access, and approval path. Schedule A cannot create the exception by itself. |
| Authorized Client contacts | Yes | [Name, title, email, phone, authority basis] |
| Authorized MIQ contacts | Yes | [Name, title, email, phone] |
| MIQ acceptance status | Yes | [Accepted / rejected / quarantined / replacement requested / pending manifest or PII Strip Confirmation] |
| Formal API or production integration | Yes | Excluded unless a separate signed integration schedule, SOW or order form, and DPA language expressly authorize the path. This Schedule may reference that separate path but cannot create it. |
| Model inference | Yes | Option A excluded unless separately authorized in the DPA, SOW, order form, processing schedule, or later written instruction. |
| Aggregate intelligence | Yes | Not authorized by this Agreement. Separate Data Participation Addendum, authenticated signup or website legal terms, SOW, order form, or product schedule that expressly activates aggregate participation or marks it default-on with opt-out available required. |
| Controlled learning or federated learning | Yes | Not authorized by this Agreement. Separate signed or versioned controlled-learning instrument required. |
| Evidence rail or evidence schedule | Yes | Not active unless a SOW or evidence schedule selects it and MIQ records verified production availability for the selected rail. Contractual selection alone does not make a rail live or available. No legal-status guarantee. |
| Source-access expiry | Yes | Earliest of completion, withdrawal, service-instrument termination, DPA termination where Client Data is involved, MIQ unsafe-path termination, or [date/event]. |
| Special exclusions or client-specific restrictions | Yes | [List all restrictions, or state "none beyond this Agreement, the DPA, and the service instrument"] |
Schedule B: Transfer Manifest And PII Strip Confirmation
Complete one row per transferred file or export package. MIQ may reject or quarantine any transfer with a missing or incomplete row.
| Category | Field | Entry or confirmation |
|---|---|---|
| Manifest | Source Access Request ID | [___] |
| Manifest | File or package name | [___] |
| Manifest | Source system | [___] |
| Manifest | Export family | [___] |
| Manifest | Scoped rooftop or entity | [___] |
| Manifest | Date range | [___] |
| Manifest | Row count if available | [___] |
| Manifest | SHA-256 or file hash if available | [___] |
| PII gate | PII Strip Confirmation reference | [___] |
| PII gate | Upload-allowed evidence | [run_summary upload_allowed true / written confirmation / other] |
| PII gate | Customer PII removed | [yes/no] |
| PII gate | Full VIN, short VIN, last-eight VIN, raw partial VIN, and raw VIN hashes removed | [yes/no] |
| PII gate | Account numbers and credentials removed | [yes/no] |
| PII gate | Free text removed | [yes/no] |
| PII gate | Staff-code treatment | [drop/code/none] |
| PII gate | Code-to-person map status | [retained by Client / not applicable / separate written handling path: ___] |
| Transfer | Transfer channel | [___] |
| Transfer | Transfer date and time | [___] |
| Transfer | Client approver | [___] |
| Transfer | MIQ recipient | [___] |
| Transfer | MIQ acceptance status | [accepted/rejected/quarantined/replacement requested] |
Schedule C: Approved Field Families And Exclusions
| Field family | Default treatment | Notes |
|---|---|---|
| Deal and stock identifiers | May be approved | Use operational identifiers such as deal number and stock number where listed in Schedule A. |
| Dates, amounts, rates, terms, counts, categories | May be approved | Use only the minimum fields needed for the service purpose. |
| Lender, product, department, and status codes | May be approved | Avoid customer-identifying or account-identifying values. |
| Postal information | FSA only where approved | Full postal code is blocked unless a later written instrument authorizes a narrower path. |
| Vehicle information | Year, make, model, trim, odometer, color may be approved | Full VIN, short VIN, last-eight VIN, raw partial VIN, and raw VIN hashes are blocked by default. |
| Staff fields | Dropped by default | Staff-code mode requires Schedule A approval; code-to-person map remains with Client. |
| Customer direct identifiers | Blocked | No names, addresses, emails, phone numbers, SINs, driver's licence numbers, dates of birth, credit bureau data, bank data, or payment-card data. |
| Credentials and access secrets | Blocked | No usernames, passwords, API secrets, tokens, cookies, MFA codes, keys, or equivalent access material. |
| Free text and unstructured documents | Blocked by default | Requires later written template-specific approval and safety proof. |
Reliance Record
This is the client-use form of the MIQ Source Access Agreement. No statement in this Agreement represents outside legal, tax, accounting, insurance, lender, regulator, privacy review, DMS-vendor, or professional approval.