Laserfiche WebLink
8.1. Security and Other Risks. Customer acknowledges that, notwithstanding security features of the <br />Subscription Service, no product, hardware, software or service can provide a completely secure mechanism <br />of electronic transmission or communication and that there are persons and entities, including enterprises, <br />governments and quasi -governmental actors, as well as technologies, that may attempt to breach any <br />electronic security measure. Subject only to its limited warranty obligations set forth in Section 6, Accela will <br />have no liability for any security breach caused by any such persons, entities, or technologies. Customer further <br />acknowledges that the Subscription Service is not guaranteed to operate without interruptions, failures, or <br />errors. If Customer or Authorized Users use the Subscription Service in any application or environment where <br />failure could cause personal injury, loss of life, or other substantial harm, Customer assumes any associated <br />risks and will indemnify Accela and hold it harmless against those risks. <br />9. SECURITY AND PERSONAL DATA <br />9.1. Security. Accela has implemented commercially viable and reasonable information security processes, <br />policies and technology safeguards to protect the confidentiality and integrity of Customer Data, personal data <br />protect against reasonably anticipated threats. Accela holds SSAE 16 /18 SOC 2, and PCI -DSS certifications and <br />leverages certified service providers who are vetted against industry standards such as ISO 27001 and SSAE 16 <br />/ 18 SOC 2 in the provision of the service. <br />9.2. Customer Data. Customer shall be responsible for Customer Data as entered in to, applied or used in the <br />Subscription Services. Customer is responsible for updating all Customer Data. In addition, Customer <br />acknowledges that Accela generally does not have access to and cannot retrieve lost Customer Data. If <br />Customer loses Customer Data, Customer may no longer have access to the Subscription Service. Customer <br />grants to Accela the non-exclusive right to process Customer Data (including personal data) for the sole <br />purpose of and only to the extent necessary for Accela: (i) to provide the Subscription Services; (ii) to verify <br />Customer's compliance with the restrictions set forth in Section 2.2 (Restrictions) if Accela has a reasonable <br />belief of Customer's non-compliance; and (iii) as otherwise set forth in this Agreement. Accela may utilize the <br />information concerning Customer's use of the Subscription Services (excluding any use of Customer's personal <br />data or Customer's Confidential Information) to improve Subscription Services, to provide Customer with <br />reports on its use of the Subscription Services, and to compile aggregate statistics and usage patterns by <br />customers using the Subscription Services. <br />9.3. Use of Aggregate_Data. Customer agrees that Accela may collect, use, and disclose quantitative data <br />derived from the use of the Subscription Services, for example, for industry analysis, benchmarking, analytics, <br />and marketing purposes. All data collected, used, and disclosed will be in aggregate form only and will not <br />identify Customer, its Authorized Users, or any third parties utilizing the Subscription Services. <br />9.4. Data Breach Notification. If directly related to Customer, Customer data, and the Subscription Services, <br />Accela shall (1) promptly inform the Customer of any known Security Incident or Data Breach, (2) reasonably <br />cooperate with Customer in addressing the known Security Incident or Data Breach, (2) promptly implement <br />measures to cure the known Security Incident or Data Breach, and (3) implement breach notification and <br />reconciliation protocols in accordance with legally required NIST -approved methods or as otherwise required <br />by law. "Security Incident" means the unauthorized access by non -authorized persons to personal data or <br />non-public data of Customer, including but not limited to the theft or loss of encrypted data. A Security Incident <br />may or may not turn into a Data Breach. "Data Breach" means the unauthorized access by a non -authorized <br />person/s that results in the use, disclosure or theft of Customer's unencrypted personal data or non-public <br />data. <br />REV: 02-10-20 PR <br />ATTY/AGR.2020.022/Accela, inc. (Page 8 of 18) <br />