Common use of Data Privacy and Security Clause in Contracts

Data Privacy and Security. A. A&M SYSTEM shall retain all right, title, and interest in and to all information, data or other content that A&M SYSTEM or its users enter, submit or upload to Services or otherwise provide to PROVIDER (collectively, the “A&M SYSTEM Data”). B. PROVIDER shall hold A&M SYSTEM Data, including without limitation, any information contained in the A&M SYSTEM Data that alone or in conjunction with other information identifies an individual, in confidence. PROVIDER shall only use or disclose A&M SYSTEM Data for the purpose of fulfilling PROVIDER’s obligations under this Agreement, as required by law, or as otherwise authorized in writing by A&M SYSTEM. PROVIDER shall restrict disclosure of A&M SYSTEM Data solely to those employees, subcontractors or agents of PROVIDER that have a need to access A&M SYSTEM Data in order for PROVIDER to perform its obligations under this Agreement. PROVIDER shall require any such subcontractors or agents to comply with the same restrictions and obligations imposed on PROVIDER in this Agreement. C. PROVIDER must promptly notify A&M SYSTEM of any legal request for A&M SYSTEM Data from a third party and take (and assist A&M SYSTEM in taking) appropriate steps not to disclose such A&M SYSTEM Data. D. PROVIDER shall, within two (2) business days of discovery, report to A&M SYSTEM Data not authorized by this Agreement or in writing by A&M SYSTEM. PROVIDER’s report must identify: (a) the nature of the unauthorized use or disclosure, (b) the A&M SYSTEM Data used or disclosed, (c) who made the unauthorized use or received the unauthorized disclosure (if known), (d) what PROVIDER has done or will do to mitigate any deleterious effect of the unauthorized use or disclosure, and (e) what corrective action PROVIDER has taken or will take to prevent future similar unauthorized use or disclosure. PROVIDER shall provide such other information, including a written report, as reasonably requested by A&M SYSTEM. E. Within thirty (30) days of the expiration or termination of this Agreement, PROVIDER, as directed by A&M SYSTEM, shall return all A&M SYSTEM Data to A&M SYSTEM in its possession (or in the possession of any of its subcontractors or agents) or delete all such A&M SYSTEM Data if return is not feasible. PROVIDER shall provide A&M SYSTEM with at least ten (10) days’ written notice of PROVIDER’s intent to delete such A&M SYSTEM Data, and shall confirm such deletion in writing.

Appears in 4 contracts

Sources: Master Services Agreement, Master Services Agreement, Master Services Agreement

Data Privacy and Security. A. A&M SYSTEM (1) The parties hereby acknowledge and agree that: (A) SRT is the exclusive owner of all right, title and interest in and to the SRT Data; (B) SRT Data is and shall retain remain confidential and proprietary information of SRT; (C) SL is the exclusive owner of all right, title and interest in and to the SL Data; and (D) SL Data is and shall remain confidential and proprietary information of SL, subject to the Privacy Requirements. With respect to any SRT Data provided by SRT to SL hereunder, except to the extent expressly permitted hereunder, subject to this Section 28, or by prior written permission of SRT, SL shall not prepare any derivative work of the SRT Data or any portion thereof, or sublicense, transfer, assign, rent, lease or otherwise convey the SRT Data or any portion thereof, or any right with respect thereto, to any third party. All right, title and interest in all SRT Data made by or on behalf of SL, together with all intellectual property rights therein, shall be owned exclusively by SRT. SL hereby assigns to SRT all right, title, and interest in such SRT Data and the intellectual property rights therein. SL shall, at the request of SRT, perform any acts that SRT may reasonably deem necessary or desirable to all informationevidence or confirm SRT’s ownership interest in such SRT Data and the intellectual property rights therein, data or other content that A&M SYSTEM or its users enter, submit or upload including but not limited to Services or otherwise provide to PROVIDER (collectively, the “A&M SYSTEM Data”)making further written assignments in a form determined by SRT. B. PROVIDER (2) In connection with the performance of the Origination Services hereunder, SL shall hold A&M SYSTEM Datacomply with the Privacy Requirements, including without limitationsubject to (i) the mandatory compliance date of such Privacy Requirements and (ii) the applicability of such Privacy Requirements to SL as the result of SL’s provision of the Origination Services under this Agreement. The foregoing obligation to comply with the Privacy Requirements may include the following: (A) SL shall not disclose any Borrower Information to any person or entity, any information contained in other than to the A&M SYSTEM Data that alone or in conjunction with other information identifies an individual, in confidence. PROVIDER shall only use or disclose A&M SYSTEM Data for the purpose of fulfilling PROVIDERextent necessary to carry out SL’s express obligations under this Agreement, as required by lawand for no other purpose. SL shall ensure that each person or entity to whom or to which SL intends to disclose Borrower Information shall, or as otherwise authorized in writing by A&M SYSTEM. PROVIDER shall restrict prior to any such disclosure of A&M SYSTEM Data solely information, agree to: (i) keep confidential any such Borrower Information and (ii) use or disclose such Borrower Information only to those employees, subcontractors or agents of PROVIDER that have a need the extent necessary to access A&M SYSTEM Data in order for PROVIDER to perform its carry out SL’s express obligations under this Agreement; (B) SL shall not use Borrower Information for any purpose, including but not limited to the marketing of products or services to, or the solicitation of business from the Borrowers. PROVIDER shall require any SL may use the Borrower Information to the extent necessary to carry out SL’s express obligations under the Agreement. SL may also use the Borrower Information as expressly permitted by SRT in writing, to the extent that such subcontractors or agents to comply express permission is in accordance with the same restrictions and obligations imposed on PROVIDER in this Agreement. C. PROVIDER must promptly notify A&M SYSTEM of any legal request for A&M SYSTEM Data from a third party and take Privacy Requirements; (and assist A&M SYSTEM in takingC) appropriate steps not to disclose such A&M SYSTEM Data. D. PROVIDER shallSL shall assess, within two (2) business days of discovery, report to A&M SYSTEM Data not authorized by this Agreement or in writing by A&M SYSTEM. PROVIDER’s report must identify: (a) the nature of the unauthorized use or disclosure, (b) the A&M SYSTEM Data used or disclosed, (c) who made the unauthorized use or received the unauthorized disclosure (if known), (d) what PROVIDER has done or will do to mitigate any deleterious effect of the unauthorized use or disclosuremanage, and (e) what corrective action PROVIDER has taken control risks relating to the security and confidentiality of Borrower Information, and shall use at least the same physical and other security measures to protect all Borrower Information in SL’s possession or will take to prevent future similar unauthorized use or disclosure. PROVIDER shall provide such other information, including a written reportcontrol, as reasonably requested by A&M SYSTEM. E. Within thirty SL uses for its own confidential and proprietary information; (30D) days of If SRT provides an Account Number to SL to enable the expiration or termination parties to carry out the purposes of this Agreement, PROVIDERSL shall use such Account Number only for such specific purpose and for no other purpose. To the extent that the obligations under (A) through (D), as directed by A&M SYSTEMinclusive, shall return all A&M SYSTEM Data to A&M SYSTEM in its possession (or in the possession of any of its subcontractors or agents) or delete all such A&M SYSTEM Data if return is immediately preceding sentence are not feasible. PROVIDER required by the Privacy Requirements, SL shall provide A&M SYSTEM with perform same upon SRT’s request at least ten (10) days’ written notice of PROVIDERSRT’s intent to delete such A&M SYSTEM Data, sole cost and shall confirm such deletion in writingexpense.

Appears in 3 contracts

Sources: Origination Services Agreement (Steward Realty Trust, Inc.), Origination Services Agreement (Steward Realty Trust, Inc.), Origination Services Agreement (Steward Realty Trust, Inc.)

Data Privacy and Security. A. The A&M SYSTEM or the applicable Member shall retain all right, title, and interest in and to all information, data or other content that the A&M SYSTEM SYSTEM, the Members, their employees, contractors, students, or its users any other third party on behalf of MEMBER enter, submit or upload to Services or otherwise provide to PROVIDER under this Agreement (collectively, the “A&M SYSTEM System Data”). A&M System Data may include information relating to employees and students, including, but not limited to personally identifiable information, social security numbers, credit card numbers, or data protected or made confidential or sensitive by applicable federal, state, and local laws, rules, and regulations. B. PROVIDER shall hold A&M SYSTEM Data, including without limitation, any information contained in safeguard and maintain the confidentiality of the A&M SYSTEM Data that alone or in conjunction accordance with other information identifies an individualapplicable federal, in confidencestate, and local laws, rules, and regulations. PROVIDER shall only use or disclose A&M SYSTEM Data for the purpose of fulfilling PROVIDER’s obligations under this Agreement, as required by law, or as otherwise authorized in writing by A&M SYSTEMSYSTEM or the applicable Member. PROVIDER shall restrict disclosure of the A&M SYSTEM Data solely to those employees, subcontractors or agents of PROVIDER that have a need to access the A&M SYSTEM Data in order for PROVIDER to perform its obligations under this Agreement. PROVIDER shall require any such subcontractors or agents to comply with the same restrictions and obligations imposed on PROVIDER in this AgreementAgreement and PROVIDER agrees that it shall be responsible for its subcontractors’ and agents’ compliance with such obligations. C. PROVIDER must promptly notify A&M SYSTEM or the applicable Member of any legal request for A&M SYSTEM Data from a third party and take (and assist A&M SYSTEM or Member in taking) appropriate steps not to disclose such A&M SYSTEM Data. D. PROVIDER shall, within two (2) business days of discovery, report to A&M SYSTEM or the applicable Member any use or disclosure of A&M SYSTEM Data not authorized by this Agreement or in writing by A&M SYSTEMSYSTEM or the applicable Member. PROVIDER’s report must identify: (a) the nature of the unauthorized use or disclosure, (b) the A&M SYSTEM Data used or disclosed, (c) who made the unauthorized use or received the unauthorized disclosure (if known)disclosure, (d) what PROVIDER has done or will do to mitigate any deleterious effect of the unauthorized use or disclosure, and (e) what corrective action PROVIDER has taken or will take to prevent future similar unauthorized use or disclosure. PROVIDER shall provide such other information, including a written report, as reasonably requested by A&M SYSTEMSYSTEM or the applicable Member. E. Within thirty (30) days of the expiration or termination of this AgreementAgreement or an Order Form, PROVIDER, as directed by A&M SYSTEMSYSTEM or the applicable Member, shall return in acceptable electronic format all A&M SYSTEM Data to A&M SYSTEM in its possession (or in the possession of any of its subcontractors or agents) or to A&M SYSTEM or, at A&M SYSTEM’s option, delete all such A&M SYSTEM Data System Data, if return is not feasible. PROVIDER shall provide A&M SYSTEM System with at least ten (10) days’ written notice of PROVIDER’s intent to delete such A&M SYSTEM System Data, and shall confirm such deletion in writing.

Appears in 2 contracts

Sources: Service Agreement, Service Agreement

Data Privacy and Security. A. The A&M SYSTEM System shall retain all right, title, and interest in and to all information, data or other content that the A&M SYSTEM System or its users employees, contractors, students, or any other third party on behalf of the A&M System enter, submit or upload to Services or otherwise provide to PROVIDER under this Agreement (collectively, the “A&M SYSTEM System Data”). B. PROVIDER shall hold A&M SYSTEM Data, including without limitation, any information contained in the A&M SYSTEM Data that alone or in conjunction with other information identifies an individual, in confidence. PROVIDER shall only use or disclose A&M SYSTEM Data for the purpose of fulfilling PROVIDER’s obligations under this Agreement, as required by law, or as otherwise authorized in writing by A&M SYSTEM. PROVIDER shall restrict disclosure of A&M SYSTEM Data solely to those employees, subcontractors or agents of PROVIDER that have a need to access A&M SYSTEM Data in order for PROVIDER to perform its obligations under this Agreement. PROVIDER shall require any such subcontractors or agents to comply with the same restrictions and obligations imposed on PROVIDER in this Agreement. C. PROVIDER must promptly notify the A&M SYSTEM System of any legal request for A&M SYSTEM System Data from a third party and take (and assist the A&M SYSTEM System in taking) appropriate steps not to disclose such A&M SYSTEM System Data. D. C. PROVIDER shall, within two (2) business days of discovery, report to the A&M SYSTEM System any use or disclosure of A&M System Data not authorized by this Agreement or in writing by A&M SYSTEMSystem. PROVIDER’s report must identify: (a) the nature of the unauthorized use or disclosure, (b) the A&M SYSTEM System Data used or disclosed, (c) who made the unauthorized use or received the unauthorized disclosure (if known), (d) what PROVIDER has done or will do to mitigate any deleterious effect of the unauthorized use or disclosure, and (e) what corrective action PROVIDER has taken or will take to prevent future similar unauthorized use or disclosure. PROVIDER shall provide such other information, including a written report, as reasonably requested by the A&M SYSTEMSystem. E. D. Within thirty (30) days of the expiration or termination of this Agreement, PROVIDER, as directed by the A&M SYSTEMSystem, shall return in acceptable electronic format all A&M SYSTEM System Data to A&M SYSTEM in its possession (or in the possession of any of its subcontractors or agents) or to the A&M System or, at the A&M System’s option, delete all such A&M SYSTEM Data System Data, if return is not feasible. PROVIDER shall provide the A&M SYSTEM System with at least ten (10) days’ written notice of PROVIDER’s intent to delete such A&M SYSTEM System Data, and shall confirm such deletion in writing.

Appears in 1 contract

Sources: Services Agreement

Data Privacy and Security. A. The A&M SYSTEM System shall retain all right, title, and interest in and to all information, data or other content that the A&M SYSTEM System or its users employees, contractors, students, or any other third party on behalf of the A&M System enter, submit or upload to Services or otherwise provide to PROVIDER under this Agreement (collectively, the “A&M SYSTEM System Data”). B. PROVIDER shall hold A&M SYSTEM Data, including without limitation, any information contained in safeguard and maintain the confidentiality of the A&M SYSTEM System Data that alone or in conjunction accordance with other information identifies an individualapplicable federal, in confidencestate, and local laws, rules, and regulations. PROVIDER shall only use or disclose A&M SYSTEM System Data for the purpose of fulfilling PROVIDER’s obligations under this Agreement, as required by law, or as otherwise authorized in writing by the A&M SYSTEMSystem. PROVIDER shall restrict disclosure of A&M SYSTEM System Data solely to those employees, subcontractors or agents of PROVIDER that have a need to access A&M SYSTEM System Data in order for PROVIDER to perform its obligations under this Agreement. PROVIDER shall require any such subcontractors or agents to comply with the same restrictions and obligations imposed on PROVIDER in this AgreementAgreement and PROVIDER agrees that it shall be responsible for its subcontractors’ and agent’ compliance with such regulations. C. PROVIDER must promptly notify the A&M SYSTEM System of any legal request for A&M SYSTEM System Data from a third party and take (and assist the A&M SYSTEM System in taking) appropriate steps not to disclose such A&M SYSTEM System Data. D. PROVIDER shall, within two (2) business days of discovery, report to the A&M SYSTEM System any use or disclosure of A&M System Data not authorized by this Agreement or in writing by A&M SYSTEMSystem. PROVIDER’s report must identify: (a) the nature of the unauthorized use or disclosure, (b) the A&M SYSTEM System Data used or disclosed, (c) who made the unauthorized use or received the unauthorized disclosure (if known), (d) what PROVIDER has done or will do to mitigate any deleterious effect of the unauthorized use or disclosure, and (e) what corrective action PROVIDER has taken or will take to prevent future similar unauthorized use or disclosure. PROVIDER shall provide such other information, including a written report, as reasonably requested by the A&M SYSTEMSystem. E. Within thirty (30) days of the expiration or termination of this Agreement, PROVIDER, as directed by the A&M SYSTEMSystem, shall return in acceptable electronic format all A&M SYSTEM System Data to A&M SYSTEM in its possession (or in the possession of any of its subcontractors or agents) or to the A&M System or, at the A&M System’s option, delete all such A&M SYSTEM Data System Data, if return is not feasible. PROVIDER shall provide the A&M SYSTEM System with at least ten (10) days’ written notice of PROVIDER’s intent to delete such A&M SYSTEM System Data, and shall confirm such deletion in writing.

Appears in 1 contract

Sources: Software as a Service Agreement