Laserfiche WebLink
Data"). These measures are designed to protect the integrity of Pilot Data and <br />guard against unauthorized or unlawful access. <br />13.2 Electronic Commerce. Vendor shall protect Pilot Data in accordance with <br />the Payment Card Industry Data Security Standard on behalf of the City, relating <br />to City activities when cardholder informatir.n entered, accessed, transferred, <br />stored or processed by Vendor or through their syster i. <br />13.3 Confidential Information. Vendor shall treat all information and data, <br />including but not limited to remote access, such as instructions, user IDs and <br />Passwords, as Confidential Information. In no case shall Vendor allow a third <br />party access to City or customer information or Pilot Data, including but not <br />limited to proprietary Confidential Information, without the express written <br />consent of the City. <br />13.4 Data Access. Protection of personal privacy and data shall be an integral <br />part of the business activities of Vendor to ensure there is no inappropriate or <br />unauthorized access or use of Pilot Data at any time. To this end, Vendor shall <br />safeguard the confidentiality, integrity and availability of City Data and comply <br />with the following conditions: <br />13.4.1 Vendor shall implement and maintain appropriate technical, <br />administrative, and organizational security measures to safeguard against <br />unauthorized access, disclosure or theft of Pilot Data. Such security <br />measures shall be in accordance with recognized industry practice. <br />13.4.2 At no time shall any Pilot Data or processes be copied, disclosed, <br />sold, or retained by Vendor or any patty related to Vendor for subsequent <br />use in any transaction that does not include the City without the City's <br />express written consent. <br />13.4.3 Vendor shall not use any information collected in connection with <br />the Services performed under this Agreement for any purpose other than <br />fulfilling the service without the City's express written consent. <br />13.5 Data Location. Vendor shall provide its services to the City solely from <br />data centers or devices located in the United States. Storage of Pilot Data at rest <br />shall be located solely in data centers or on devices in the U.S. Vendor shall <br />permit its personnel and contractors to access Pilot Data remotely only as <br />required to provide technical support or other support specifically requested by <br />the City. <br />13.6 Security Incident or Data Breach Notification. Vendor shall inform the City <br />immediately of any security incident or data breach, cooperate with the City in <br />addressing the matter, promptly implement measures to cure the breach, and <br />implement breach notification and reconciliation protocols in accordance with <br />NIST -approved methods as directed by the City. <br />REV: 09-13-19 DZ <br />ATTY/AGR.2019.245/Equipped Systems Inc. (Page 5 of 12) <br />