Laserfiche WebLink
12.2.6 Consultant shall not use any information collected in connection <br />with the Services issued from this Agreement for any purpose other than <br />fulfilling the Services. <br />12.3 Data Location. Consultant shall provide its Services to the City and its end <br />users solely from data centers in the U.S. Storage of City Data at rest shall be <br />located solely in data centers in the U.S. Consultant shall not allow its personnel <br />or contractors to store City Data on portable devices, including personal <br />computers, except for devices that are used and kept only at its U.S. data <br />centers. Consultant shall permit its personnel and contractors to access City <br />Data remotely only as required to provide the Services or to provide technical <br />support. Consultant may provide technical user support on a 24/7 basis using a <br />Follow the Sun model, unless otherwise prohibited in this Agreement. <br />12.4 Securitv Incident or Data Breach Notification. Consultant shall inform the <br />City of any Security Incident or Data Breach: <br />12.4.1 Incident Response: Consultant may need to communicate with <br />outside parties regarding a Security Incident, which may include <br />contacting law enforcement, fielding media inquiries and seeking external <br />expertise as mutually agreed upon, defined by law or contained in this <br />Agreement. Discussing Security Incidents with the City should be handled <br />on an urgent as -needed basis, as part of Consultant communication and <br />mitigation processes as mutually agreed upon, defined by law or <br />contained in this Agreement. <br />12.4.2 Security Incident Reporting Requirements: Consultant shall report a <br />Security Incident to the appropriate City Identified Contact immediately. <br />12.4.3 Breach Reporting Requirements: If Consultant has actual <br />knowledge of a confirmed Data Breach that affects the security of any City <br />content that is subject to applicable Data Breach notification law, <br />Consultant shall (1) promptly notify the appropriate City Identified Contact <br />within 24 hours or sooner, unless shorter time is required by applicable <br />law, and (2) take commercially reasonable measures to address the Data <br />Breach in a timely manner. <br />12.5 Breach Responsibilities. This section only applies when a Data Breach <br />occurs with respect to Personal Data or Non -Public Data within the possession or <br />control of Consultant. <br />12.5.1 Consultant, unless stipulated otherwise, shall immediately notify the <br />appropriate City Identified Contact by telephone in accordance with the <br />agreed upon security plan or security procedures if it reasonably believes <br />there has been a Security Incident. <br />REV: 01-10-18 JS Page 7 of 18 <br />ATTY/AGR.2018.007/Brainfuse 2018 <br />