|
Agreement No. 351-2203909
<br />Managed Services Subscription Agreement (03.26.20) Page 2 of 12
<br />This document and any attachments are for the sole use of the intended recipients and contain confidential and proprietary information.
<br />Any unauthorized use, disclosure or distribution of this document or its attachments is prohibited.
<br />RFI may process in the course of performing the Managed
<br />Services.
<br />“SDI” means Subscriber’s system and device information
<br />transmitted for purposes of use and performance of the
<br />Services.
<br />4. Data Security and Confidentiality.
<br />a. RFI and Subscriber each will (i) maintain throughout
<br />the Subscription Period best practices, industry-appropriate
<br />technical and organizational measures, in compliance with
<br />applicable laws (including without limitation Data Protection
<br />Laws), to protect against Data Breach all Confidential
<br />Information which it respectively collects, stores, transports,
<br />transmits or processes (or exposes for collection,
<br />processing, transporting, transmission or processing) by or
<br />in connection with the Managed Services; and (ii) promptly
<br />notify the other of any suspected or discovered Data Breach
<br />and provide all commercially reasonable cooperation and
<br />assistance to the other to investigate, mitigate and
<br />remediate it. RFI also will provide Subscriber all
<br />commercially reasonable assistance required by Subscriber
<br />to enable Subscriber to respond to, comply with or
<br />otherwise resolve any request, question or complaint
<br />received by Subscriber from any applicable data protection
<br />authority or from any living individual whose Personal
<br />Information is processed by RFI or the Service on behalf of
<br />Subscriber, at RFI’s expense in the case if a Data Breach
<br />caused by RFI’s negligence or breach of any Data
<br />Protection Laws.
<br />b. Without qualification of Section 4(a), each party (as
<br />“Recipient”) shall take all necessary precautions to keep
<br />secure and confidential all Confidential Information received
<br />from the other party (as “Discloser”); refrain from using
<br />Confidential Information except for purposes of performing
<br />its duties and exercising its rights under this Agreement;
<br />disclose the Confidential Information only to Recipient’s
<br />staff, professional advisers and subcontractors, on a “need
<br />to know” basis for such purposes, who are subject to
<br />obligations of confidentiality in relation to such Confidential
<br />Information which are no less stringent than the Recipient’s
<br />obligations of confidentiality under this Agreement; and
<br />refrain from disclosing it to any other person outside the
<br />Recipient’s organization without the prior written agreement
<br />of the Discloser.
<br />c. Section 4(b) shall not impair Recipient’s right to use
<br />and disclose otherwise Confidential Information that:
<br />(i) Recipient possessed without an obligation of confidence
<br />before receiving it from Discloser; (ii) Recipient developed
<br />or had developed for it independently without violation of
<br />Section 4(b); (iii) Recipient obtains from a third party who
<br />has no obligation of confidence as to it; (iv) becomes
<br />publicly available through no breach of this Agreement; or
<br />(v) Recipient is required to disclose by order of a court or by
<br />a government body or agency or by the listing rules of any
<br />stock exchange, provided Recipient shall notify Discloser of
<br />the requirement, sufficiently promptly (if commercially
<br />feasible) for Discloser to have the opportunity to seek a
<br />protective order.
<br />5. Data Authorization; Appropriate Use.
<br />a. Subject to Section 4, Subscriber authorizes RFI to
<br />access SDI as necessary for performance of the Managed
<br />Services. RFI will process SDI only for the purpose of
<br />providing the Managed Services in accordance with
<br />Subscriber’s documented instructions and applicable Data
<br />Protection Laws, and shall maintain its confidentiality in
<br />accordance with Subscriber’s instructions and as required
<br />for that purpose or by law. For such purposes, RFI may
<br />employ subcontractors for cloud infrastructure, hosting and
<br />data analysis functions, who shall be bound by restrictions
<br />at least as strict as those set forth herein, and for whose
<br />acts, errors or omissions RFI shall remain responsible to
<br />Subscriber. RFI may collect and use anonymized and
<br />aggregated analytical information for statistical and
<br />business purposes including service improvement.
<br />c. RFI, reserves all of its respective current and future
<br />intellectual property rights in the Managed Services not
<br />explicitly granted herein. Subscriber shall not assert any
<br />right, title or interest in or to those of the other or any
<br />derivative works thereof. No license, title, ownership interest
<br />or other rights therein are granted other than the access and
<br />use rights expressly granted. Subscription is non-exclusive
<br />and non-transferable. Subscriber shall not without prior
<br />express, written permission of RFI, (i) license, sublicense,
<br />sell, resell, transfer, assign, distribute or otherwise
<br />commercially exploit or make available to any third party any
<br />element of the Services in any way; or (ii) “frame” or “mirror”
<br />any content from the Services on any server or wireless or
<br />internet-based device. Subscriber shall not modify,
<br />translate, reverse engineer, disassemble or decompile any
<br />software or agents furnished by RFI, except to the extent
<br />such actions cannot be prohibited under applicable law.
<br />c. In the case of Managed Services including Viakoo,
<br />the authorizations and reservations of rights set forth in
<br />Sections 5(a) and (b) also shall extend to Viakoo.
<br />d. Subscriber shall not use the Managed Services in
<br />any manner not in accordance with their intended uses or
<br />violate or attempt to violate or circumvent their security
<br />procedures. Subscriber shall immediately notify RFI of any
<br />unauthorized use of Subscriber’s account or any other
<br />breach of security that is known to or suspected by
<br />Subscriber relative to the Service. In case any Personal
<br />Information may be processed in the course of the Managed
<br />Services, Subscriber shall comply with all applicable Data
<br />Protection Laws, including maintaining a privacy policy that
<br />permits such processing, ensuring it has all necessary rights
|