Laserfiche WebLink
12.1 Data Ownership. City will own all right, title and interest in its data that is <br />related to the Services provided under this Agreement except for data that is <br />owned by Participating Students. Consultant shall not access City user accounts <br />or City Data, except (1) as necessary to provide the Services, (2) in response to <br />service or technical issues, (3) as required by the express terms of this <br />Agreement or (4) at City's written request. <br />12.2 Data Protection. Protection of personal privacy and data shall be an <br />integral part of the business activities of Consultant to ensure there is no <br />inappropriate or unauthorized use of City's data at any time. To this end, <br />Consultant shall safeguard the confidentiality, integrity, and availability of City <br />information and City Data and comply with the following conditions: <br />12.2.1 Consultant shall implement and maintain appropriate <br />administrative, technical and organizational security measures to <br />safeguard against unauthorized access, disclosure or theft of Personal <br />Data and Non -Public Data. Such security measures shall be in <br />accordance with recognized industry practice and not less stringent than <br />the measures Consultant applies to its own Personal Data and Non -Public <br />Data of similar kind. <br />12.2.2 All data obtained by Consultant in the performance of this <br />Agreement shall become and remain the property of the City. <br />12.2.3 All Personal Data and Non -Public Data shall be encrypted at rest <br />and in transit with controlled access. Unless otherwise stipulated, <br />Consultant is responsible for encryption of the Personal Data and Non - <br />Public Data. Any stipulation of responsibilities will identify specific roles <br />and responsibilities and shall be included in a service level agreement <br />signed by Consultant and City. <br />12.2.4 Consultant warrants and represents that it is PCI -DSS SAQ-D <br />compliant and that any data transmitted by the Services will be sent via <br />industry -standard PCI -compliant means. For data at rest, Consultant shall <br />ensure hard drive encryption consistent with validated cryptography <br />standards as referenced in FIPS 140-2, Security Requirements for <br />Cryptographic Modules for all Personal Data. <br />12.2.5 At no time shall any data or processes — that either belong to or <br />are intended for the use of City or its officers, agents or employees — be <br />copied, disclosed or retained by Consultant or any party related to <br />Consultant for subsequent use in any transaction that does not include the <br />City. <br />REV: 01-10-18 JS Page 6 of 18 <br />ATTY/AGR.2018.007/Brainfuse 2018 <br />