Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects. (b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws. (c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data. (d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems. (e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date. (f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 4 contracts
Sources: Business Combination Agreement (Integrated Wellness Acquisition Corp), Business Combination Agreement (Integrated Wellness Acquisition Corp), Business Combination Agreement (TortoiseEcofin Acquisition Corp. III)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group To the Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of , each Group Company has implemented adequate written policies relating to the Processing of Personal Data as and to the extent required by applicable Law (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There are To the Company’s knowledge, there is (and since the Lookback Date there has been) no material Proceeding pending Proceedingsor, nor has there been any Proceedings to the Company’s knowledge, threatened against or involving any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iiiii) any other Governmental Entity Entity, foreign or domestic; or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Group Company is or was in violation of any applicable Privacy LawsLaws or any Privacy and Data Security Policies nor, to the Company’s knowledge, is there (nor since the Lookback Date has there been) any basis for the foregoing.
(c) Since To the Company’s knowledge, since the Lookback Date, : (i) there no person has been no material alleged or given written notice of unauthorized accessaccess to, or use, acquisition disclosure, or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group Company, and ; (ii) to the Company’s knowledge, there have been no person has alleged or given written notice of unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date Systems; and (iii) none of the Group Companies is aware has notified or been required to notify any Person of any written or(A) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach (B) other unauthorized or incident. None of the Group Companies has received any written complaintsunlawful access to, claimsor use, demands, inquiries disclosure or other noticesProcessing of, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data, except, in each case, as would not have a Company Material Adverse Effect.
(d) Each Group Company owns or has a license to use the such Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the All Company IT Systems.
Systems are: (ei) The Group Companies are free from any material defect, bug, virus or programming, design or documentation error and have been (ii) in compliance in sufficiently good working condition to effectively perform all material respects with all applicable Privacy information technology operations necessary for the operation of the Business (except for ordinary wear and Security Requirements tear). To the Company’s knowledge, since the Lookback Date.
(f) The Group Companies , there have implemented reasonable physicalnot been any material failures, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security breakdowns or continued substandard performance of all any Company IT Systems and Personal Data in their possession that have caused a material failure or control from unauthorized access by any Person, including each disruption of the Group Companies’ employees and contractorsCompany IT Systems other than routine failures or disruptions that have been remediated in the ordinary course of business.
Appears in 4 contracts
Sources: Business Combination Agreement (Adagio Medical Holdings, Inc.), Business Combination Agreement (Chain Bridge I), Business Combination Agreement (ARYA Sciences Acquisition Corp IV)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process The Company’s and its Subsidiaries’ data, privacy and security practices and processing of Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements comply in all material respectsrespects with the Privacy Laws. Neither the execution, delivery and performance of this Agreement will cause, constitute, or result in a breach or violation of any Privacy Laws.
(b) There are no pending ProceedingsThe Company and its Subsidiaries have established and maintain appropriate technical, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, physical and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been organizational measures in compliance in all material respects with all applicable data security requirements under the Privacy and Security Requirements since the Lookback DateLaws.
(fc) The Group Companies Neither the Company nor any of its Subsidiaries have implemented reasonable physicalreceived or experienced any Legal Proceeding, technical and administrative safeguards Order, warrant, regulatory opinion, audit result or written notice from a Governmental Entity or any other Person in the last three (3) years: (i) alleging or confirming material non-compliance with a relevant requirement of Privacy Laws; or (ii) giving notice of any Governmental Entity’s investigation, requisition of information from, or intention to protect enter the privacypremises of, operationthe Company or any of its Subsidiaries with respect to alleged or confirmed material non-compliance with a relevant requirement of Privacy Laws.
(d) During the last three (3) years, confidentiality(i) no material security incident, integrity and including, but not limited to, malware, ransomware, virus, compromise of credentials, denial-of-service attack, unauthorized intrusion, violation of any data security of all Company IT Systems and policy, breach, or unauthorized access in relation to ICT Infrastructure, Confidential Information, Intellectual Property or Personal Data in their possession the Company’s or any of its Subsidiaries’ possession, custody or control from unauthorized access by has occurred and (ii) no data breach has occurred for which the Company or any of its Subsidiaries has been required under Privacy Laws to notify a Governmental Entity or any other Person, including each of the Group Companies’ employees and contractors.
Appears in 3 contracts
Sources: Share Purchase Agreement, Share Purchase Agreement, Share Purchase Agreement (Nvidia Corp)
Data Privacy and Security. (ai) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company and each of its Subsidiaries complies, and during the past three years has safeguards complied, in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance all material respects, with all Privacy and Information Security Requirements Requirements. Neither the Company nor any of its Subsidiaries have been notified in all material respects.
(b) There are no pending Proceedingswriting of, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) or is the United States Federal Trade Commissionsubject of, any state attorney general complaint or similar state official; (iii) any other Governmental Entity proceeding or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any, regulatory investigation related to Processing of Personal Data by any third party service provider on behalf Governmental Entity or payment card association, regarding any actual or possible violations of any Group Company, Privacy and Information Security Requirement by or with respect to the Company or any of its Subsidiaries.
(ii) The Company and each of its Subsidiaries employs commercially reasonable organizational, administrative, physical and technical safeguards that comply in all material respects with all Privacy and Information Security Requirements to protect Company Data within its custody or control and requires the same of all vendors under contract with the Company that Process Company Data on its behalf. The Company and each of its Subsidiaries have provided all requisite notices and obtained all required consents, and satisfied all other requirements (including but not limited to notification to Governmental Entities), necessary for the Processing (including international and onward transfer) of all Personal Data in connection with the conduct of the business as currently conducted and in connection with the consummation of the transactions contemplated hereunder.
(iii) To the knowledge of the Company, neither the Company nor any of its Subsidiaries has suffered a security breach with respect to any of the Company Data and to the Company’s knowledge, there have has been no unauthorized intrusions into or Security Breaches illegal use of or access to any Company Data. Neither the Company nor any of its Subsidiaries has notified, or been required to notify, any Person of any Group information security breach involving Personal Data. To the Company’s knowledge, the Company systems networksSystems have had no material errors or defects that have not been fully remedied and contain no code designed to disrupt, communication equipment disable, harm, distort or otherwise impede in any manner the legitimate operation of such Company Systems (including what are sometimes referred to as “viruses”, “worms”, “time bombs” or “back doors”) that have not been removed or fully remedied. Neither the Company nor any of its Subsidiaries have experienced within the past three years any material disruption to, or material interruption in, the conduct of its business that affected the business for more than one calendar week, and attributable to a defect, bug, breakdown, unauthorized access, introduction of a virus or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification ofmalicious programming, or interference with Company IT Systems since other failure or deficiency on the Lookback Date and none of the Group Companies is aware part of any written or, to the knowledge of the Company, oral notices computer software or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 3 contracts
Sources: Arrangement Agreement (Canopy Growth Corp), Arrangement Agreement (Canopy Growth Corp), Arrangement Agreement (Acreage Holdings, Inc.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards and its Subsidiaries have developed, implemented and maintained a written data protection, data privacy and cybersecurity program (the “Data Protection Program”) that is in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in material compliance with all Privacy Requirements. The Company and its Subsidiaries have not experienced any material Security Requirements Incident. Since January 1, 2018, no Person has brought, or threatened in all material respectswriting to bring, any Action against the Company or any of its Subsidiaries in relation to any actual or alleged Security Incident or violation or breach of any Privacy Requirement.
(b) There are no pending ProceedingsSince January 1, nor has there been any Proceedings against any Group 2018, the Company initiated by (i) any Person; (ii) and its Subsidiaries have at all times complied in all material respects with all Privacy Requirements with respect to the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by Personally Identifiable Information and other data. The Company and its Subsidiaries are not and since January 1, 2018, have not been subject to a Governmental Order of, or on behalf of have received a Group Company is in notice from, a Governmental Authority regarding actual or alleged non-compliance with or violation of any Privacy Requirement. The Company and its Subsidiaries have taken commercially reasonable steps to ensure the reliability of their employees, representatives, consultants, contractors and agents that have access to Company PII, to train such individuals on all applicable Privacy LawsRequirements and to ensure that all such employees, representatives, consultants, contractors and agents with the right to access such Company PII are under written obligations of confidentiality with respect to such Company PII.
(c) Since To the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure knowledge of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches illegal Processing, or other breach, violation or default (or event that, with or without the giving of notice or lapse of time, would constitute a breach, violation or default) of any Group Company systems networksPrivacy Requirements by any third-party data suppliers, communication equipment vendors or other technology necessary for the operations partners that Process any Company PII or other Personally Identifiable Information on behalf of the Group Companies’ businessCompany or its Subsidiaries. The Group Companies No circumstances have not experienced arisen in which the Privacy Requirements would require or recommend the Company or its Subsidiaries to notify any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware Governmental Authority of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataIncident.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business The consummation of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systemstransactions contemplated by this Agreement will not breach any Privacy Requirement.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 3 contracts
Sources: Agreement and Plan of Merger (Tuatara Capital Acquisition Corp), Agreement and Plan of Merger (Tuatara Capital Acquisition Corp), Merger Agreement (Tuatara Capital Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process has implemented written policies relating to the Processing of Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each extent required by Privacy and Data Security Requirements. Each Group Company (including with respect to employee matters) are is and has been in compliance in all material respects with all Privacy and Data Security Requirements in all material respectsrelevant jurisdictions.
(b) There are no No Group Company has received notice of any pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityEntity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Lawsand Data Security Requirements. No Group Company has been notified in writing, or been required by Privacy and Data Security Requirements to notify in writing, any Person or entity of any personal data or information security-related incident.
(c) Since the Lookback Dateincorporation of the Company, (i) there has been no material loss, damage, unauthorized access, use, acquisition breach of security of any Company IT Systems or disclosure of Personal Data, Data or confidential business Company information in the possession possession, custody or control of any Group Company oror otherwise held or processed on its behalf and (ii) there has been no failure, breakdown, continued substandard performance, data loss, outage, unscheduled downtime, unauthorized intrusion, or breach of security or technology security or any related incident affecting any such Company IT Systems that has impacted the integrity or availability of the Company IT Systems or that have caused or could reasonably be expected to result in the substantial disruption of or interruption in or to the Company’s knowledgeuse of such Company IT Systems or the conduct and operation of the business of the Group Companies, any except, in the case of clauses (i) and (ii), as would not have a Company Material Adverse Effect.
(d) Each Group Company has implemented, and required that its third party service provider vendors implement, adequate policies and commercially reasonable security (i) regarding the confidentiality, integrity, and availability of personal data, and business proprietary or sensitive information, in its possession, custody, or control, or held or processed on behalf of any Group Companyits behalf, and (ii) to regarding the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations integrity and availability of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataSystems.
(de) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Company IT Systems are adequate in all material respects for the operation and conduct of the business of the Group Companies have a sufficient number as currently conducted. To the knowledge of license seats for all the Company, neither the Company IT Systems nor any Software included in that constitutes Company Owned Intellectual Property contains any viruses, worms, Trojan horses, bugs, faults or other devices, errors, contaminants or effects that (i) materially disrupt or materially adversely affect the functionality of the Company IT Systems.
, except as disclosed in their documentation or (eii) enable or assist any Person to access without authorization any Company IT Systems. The Group Companies are and have been consummation of the transaction contemplated by this Agreement will not result in compliance in all material respects with all applicable any violation of any Privacy and Data Security Requirements since the Lookback DateRequirements.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 2 contracts
Sources: Business Combination Agreement (HighCape Capital Acquisition Corp.), Business Combination Agreement (HighCape Capital Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process The Company’s data privacy and security practices and processing of Personal Data contrary to lawcomply, to each Group Company’s knowledgeand at all times have complied, with all of the Company Privacy Commitments, Privacy Laws and Company Data Agreements. The Company has safeguards in place that are sufficient to protect at all times required by Privacy Laws and Company Data Agreements: (A) had a valid legal basis (including providing adequate notice and obtaining any necessary consents from individuals) required for the Processing of Personal Data as conducted by or for the Company, (B) refrained from selling or sharing Personal Data with third parties for the third party’s benefit except as allowed under Applicable Law, and confidential (C) abided by any privacy rights and choices (including privacy by default obligations under Applicable Law and data-subject opt-out preferences) of individuals relating to Personal Data (such obligations along with all statements and obligations contained in Company Privacy Policies, collectively, “Company Privacy Commitments”). The Company has not granted any options, rights of first refusal or negotiation or other similar rights, licenses or agreements of any kind relating to any Company Data, and the Company is not bound by or a party to any option, rights of first refusal or negotiation or other similar rights, license or agreement of any kind with respect to any of the Company Data. Neither the execution, delivery and performance of this Agreement nor the taking over by Acquirer of all of the Company Data and other information in relating to the Company’s possession end users, employees, vendors or control from unauthorized access clients, or any other category of individuals, will cause, constitute or result in a breach or violation of any Privacy Laws or Company Privacy Commitments, any Company Data Agreements or any standard terms of service entered into by third Persons the Company with individuals the Personal Data of whom is Processed by the Company or its Processors. Copies of all current and prior Company Privacy Policies have been made available to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) Acquirer and such copies are in compliance with all Privacy true, correct and Security Requirements in all material respectscomplete.
(b) There The Company has established and maintain appropriate technical, physical and organizational measures and security systems and technologies in compliance with all data security and other applicable requirements under Privacy Laws and Company Privacy Commitments that are no pending Proceedings, nor has there been any Proceedings against any Group designed to protect Company initiated by Data against: (i) any Personaccidental or unlawful Processing or disclosure; (ii) the United States Federal Trade Commission, any state attorney general or similar state officialbreaches of confidentiality; (iii) any other Governmental Entity unavailability of Company Data; or (iv) any regulatory or self-regulatory entityother events which affect the integrity of Company Data, in each case, alleging that any in a manner appropriate to the risks represented by the Processing of such data by the Company, their data processors and any other third party with whom the Company has shared such Company Data (such processors and foregoing third parties, collectively, “Processors”). The Company has taken commercially reasonable steps to ensure the compliance of their respective employees and contractors who have access to Company Data, to train such employees on all applicable aspects of any Privacy Law and Company Privacy Commitments and to ensure that all employees with the authority and/or ability to access such data are under written obligations of confidentiality with respect to such data. The Company has a process in place for identifying Personal Data by or in the materials they offer to their users on behalf their websites and takes appropriate steps to ensure they are able legally to use such Personal Data as part of a Group Company is in violation of any applicable Privacy Lawsits commercial offering.
(c) Since the Lookback DateThe Company has not received or experienced and there is no circumstance (including any circumstance arising as a result of an audit or inspection carried out by any Governmental Entity) that would reasonably be expected to give rise to, any Legal Proceeding, Order, notice, communication, warrant, regulatory opinion, audit result or allegation from a Governmental Entity or any other Person (including an end user): (A) alleging or confirming non-compliance with a relevant requirement of Privacy Laws or Company Privacy Commitments, (iB) there has been requiring or requesting the Company to amend, rectify, cease Processing, de-combine, permanently anonymize, block or delete any Company Data, (C) permitting or mandating relevant Governmental Entities to investigate, requisition information from, or enter the premises of, the Company or (D) claiming compensation from the Company. There are no material unauthorized unsatisfied requests from individuals or other third parties to the Company seeking to exercise any data protection or privacy rights (such as rights to access, userectify, acquisition or disclosure delete Personal Data, to restrict or object to processing of Personal Data, or confidential business information relating to data portability). The Company has not been involved in any Legal Proceedings involving non-compliance or alleged non-compliance with Privacy Laws or Company Privacy Commitments.
(d) Schedule 2.11(d) of the possession or control Company Disclosure Letter contains the complete list of any Group notifications and registrations made by the Company or, to under Privacy Laws with relevant Governmental Entities in connection with the Company’s knowledgeProcessing of Personal Data. All such notifications and registrations are valid, any third party service provider on behalf of any Group Companyaccurate, complete and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written orfully paid up and, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None the consummation of the Group Companies has received any written complaints, claims, demands, inquiries Transactions will not invalidate such notification or other notices, including a notice of investigation, from any Person (including any Governmental Entity registration or self-regulatory authority) regarding any require such notification or registration to be amended. To the knowledge of the Group Companies’ Company, other than the notifications and registrations set forth on Schedule 2.11(d) of the Company Disclosure Letter, no other registrations or notifications are required in connection with the Processing of Personal Data or compliance with applicable Privacy and Security Requirementsby the Company. Since The Company does not Process the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use Personal Data of any Company IT System natural person who is under the age of 13 or Personal Data.
(d) Each Group Company owns or has is otherwise considered a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systemschild under Applicable Law.
(e) The Group Companies are Company has made available to Acquirer true, correct and complete copies of all Contracts permitting a Processor to Process Personal Data and such Processors have been in compliance in all material respects with all applicable Privacy and Security Requirements since not breached any such Contracts pertaining to Personal Data Processed by such Persons on behalf of the Lookback DateCompany.
(f) The Group Companies have implemented reasonable physicalCompany maintains complete, technical accurate and administrative safeguards up to protect the privacy, operation, confidentiality, integrity and security date records of (i) all Company IT Systems and Processing activities of Personal Data and their lawful bases and (ii) all data protection impact assessments, in their possession or control from unauthorized access each case as required by any Person, including each of the Group Companies’ employees and contractorsapplicable Privacy Laws.
Appears in 2 contracts
Sources: Agreement and Plan of Merger (Versus Systems Inc.), Merger Agreement (Versus Systems Inc.)
Data Privacy and Security. (a) Each Group Company does There is not knowingly collect or process Personal Data contrary to lawcurrently pending or, to each Group the Company’s knowledge. The Company , threatened, and there has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedingsnot been any, nor has there been any Proceedings Proceeding against any Company Group Company Member initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iiiii) any other Governmental Entity Entity, foreign or domestic; (iii) any regulatory entity, privacy regulator or otherwise, or (iv) any regulatory or self-regulatory entityother Person, in each case, alleging with respect to privacy, cybersecurity, and, to the Company’s knowledge, there are no facts upon which such a Proceeding could be based.
(b) There have not been any actual, suspected, or alleged material Security Incidents or actual or alleged claims related to material Security Incidents, and, to the Company’s knowledge, there are no facts or circumstances which could reasonably serve as the basis for any such allegations or claims. There are no data security, information security, or other technological vulnerabilities with respect to the Company Group’s services or with respect to the Company IT Systems that any Processing of Personal Data by would have a materially adverse impact on their operations or on behalf of cause a Group Company is in violation of any applicable Privacy Lawsmaterial Security Incident.
(c) Since The Company Group Members own or have license to use pursuant to a Company Material Contract the Lookback DateCompany IT Systems as necessary to operate their respective businesses as currently conducted and such Company IT Systems are sufficient for the operation of their respective businesses as currently conducted. The Company Group Members have back-up and disaster recovery arrangements, (i) there has been no material unauthorized access, use, acquisition or disclosure procedures and facilities for the continued operation of Personal Data, or confidential business information its businesses in the possession or control event of a failure of the Company IT Systems that are, in the reasonable determination of the Company, commercially reasonable and in accordance in all material respects with standard industry practice. There has not been any Group Company material disruption, failure or, to the Company’s knowledge, unauthorized access with respect to any third party service provider on behalf of the Company IT Systems that has not been remedied, replaced or mitigated in all material respects. To the Company’s knowledge, none of the Company IT Systems contain any worm, bomb, backdoor, trap doors, Trojan horse, spyware, keylogger software, clock, timer or other damaging devices, malicious codes, designs, hardware component, or software routines that causes the Company Software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized person.
(d) The Company Group Members have, and have had, in place reasonable and appropriate administrative, technical, physical and organizational measures and safeguards to (i) ensure the integrity, security, and the continued, uninterrupted, and error-free operation of the Company IT Systems, and the confidentiality of the source code of any Group CompanyCompany Software, and (ii) to the Company’s knowledgeprotect Business Data against loss, there have been no damage, and unauthorized intrusions into or Security Breaches of any Group Company systems networksaccess, communication equipment use, modification, or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Datamisuse.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 2 contracts
Sources: Merger Agreement (Assure Holdings Corp.), Merger Agreement (Akerna Corp.)
Data Privacy and Security. (ai) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company and each of its Subsidiaries complies, and during the past two years has safeguards complied, in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance all material respects, with all Privacy and Information Security Requirements Requirements. Neither the Company nor any of its Subsidiaries have been notified in all material respects.
(b) There are no pending Proceedingswriting of, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) or is the United States Federal Trade Commissionsubject of, any state attorney general complaint, regulatory investigation or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any proceeding related to Processing of Personal Data by any third party, Governmental Entity or on behalf of a Group Company is in violation payment card association, regarding any material violations of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition and Information Security Requirement by or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, with respect to the Company’s knowledge, Company or any third party service provider on behalf of any Group Company, and its Subsidiaries;
(ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches The Company and each of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance its Subsidiaries employs commercially reasonable safeguards that comply in all material respects with all applicable Privacy and Information Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect Company Data within its custody or control and requires the privacy, operation, confidentiality, integrity and security same of all vendors under contract with the Company IT Systems that Process Company Data on its behalf. The Company and each of its Subsidiaries have provided all requisite notices and obtained all required consents, and satisfied all other requirements (including but not limited to notification to applicable Governmental Entities), necessary for the Processing (including international and onward transfer) of all Personal Data in their possession or control from unauthorized access by any Person, including each connection with the conduct of the Group Companies’ employees business as currently conducted and contractorsin connection with the consummation of the transactions contemplated hereunder; and
(iii) Neither the Company nor any of its Subsidiaries, to the Company’s knowledge, has suffered a security breach with respect to any of the Company Data and, to the Company’s knowledge, there has been no unauthorized or illegal use of, access or disclosure to, or unavailability of any Company Data. Neither the Company nor any of its Subsidiaries has notified, or been required to notify, any Person of any information security breach or other incident involving Personal Data. To the Company’s knowledge, the Company Systems have had no material errors or defects that have not been fully remedied and contain no code designed to disrupt, disable, harm, distort, or otherwise impede in any manner the legitimate operation of such Company Systems (including what are sometimes referred to as “viruses,” “worms,” “time bombs,” or “back doors”) that have not been removed or fully remedied. Neither it nor any of its Subsidiaries, have experienced any disruption to, or interruption in, the conduct of its business that effected the business for more than one calendar week, and attributable to a defect, bug, breakdown, unauthorized access, introduction of a virus or other malicious programming, or other failure or deficiency on the part of any computer software or the Company Systems.
Appears in 2 contracts
Sources: Arrangement Agreement (Cresco Labs Inc.), Arrangement Agreement (Columbia Care Inc.)
Data Privacy and Security. (aA) Each Group Company does not knowingly collect Except as would not, individually or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession aggregate, reasonably be expected to result in a Material Adverse Effect or control from unauthorized access by third Persons as otherwise disclosed in the Registration Statement, the Pricing Disclosure Package and to ensure that the operation Final Prospectus, (A) the Company and each of the businesses of each Group Company (including with respect to employee matters) its Designated Subsidiaries have complied and are presently in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedingsrespects with all internal and external privacy policies, nor has there been contractual obligations, industry standards, applicable laws, statutes, judgments, orders, rules and regulations of any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general court or similar state official; (iii) arbitrator or other governmental or regulatory authority and any other Governmental Entity or (iv) any regulatory or self-regulatory entitylegal obligations, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since relating to the Lookback Date, (i) there has been no material unauthorized accesscollection, use, acquisition transfer, import, export, storage, protection, disposal and disclosure by the Company or disclosure any of Personal its Designated Subsidiaries of personal, personally identifiable, household, sensitive, confidential or regulated data (“Data Security Obligations,” and such data, “Data, ”); (B) the Company has not received any notification of or confidential business information in the possession or control of complaint regarding material non-compliance with any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, Data Security Obligation; and (iiC) to the Company’s knowledgethere is no action, there have been no unauthorized intrusions into suit or Security Breaches of proceeding by or before any Group Company systems networkscourt or governmental agency, communication equipment authority or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written body pending or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or selfthreatened alleging non-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and any Data Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataObligation.
(dii) Each Group The Company owns and each of its Designated Subsidiaries have implemented and maintain controls, policies, procedures, and technological safeguards reasonably consistent with industry standards and practices that are designed to protect against and prevent breach, destruction, loss, unauthorized distribution, use, access, disablement, misappropriation or modification, or other compromise or misuse of or relating to any information technology system or Data used in connection with the operation of the Company’s and its subsidiaries’ businesses (“Breach”). Except as would not, individually or in the aggregate, reasonably be expected to result in a Material Adverse Effect or as otherwise disclosed in the Registration Statement, the Pricing Disclosure Package and the Final Prospectus, (a) there has a license to use been no such Breach, and (b) the Company IT Systems as necessary to operate the business and its Designated Subsidiaries have not been notified of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have no knowledge of any event or condition that would reasonably be expected to result in, any such Breach, except for those that have been in compliance in all remedied without material respects with all applicable Privacy and Security Requirements since cost or liability or the Lookback Dateduty to notify any governmental or regulatory authority.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 2 contracts
Sources: Underwriting Agreement (SiriusPoint LTD), Underwriting Agreement (SiriusPoint LTD)
Data Privacy and Security. (a) Each Group Company does not knowingly collect involved in the collection or process Processing of Personal Data contrary has implemented and, where applicable, posted written privacy notices relating to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect the Processing of Personal Data to the extent required by applicable Privacy Laws (“Privacy and confidential information in the Company’s possession or control from unauthorized access by third Persons Data Security Policies”) and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are is in compliance with all Privacy and Security Requirements in all material respectsrespects with such Privacy and Data Security Policies.
(b) There To the Company’s knowledge, there are no pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory entity or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Policies.
(c) Since the Lookback Date, to the Company’s knowledge (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider acting on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business, except in the case of clauses (i) and (ii), as would not be have a Company Material Adverse Effect. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company’s knowledge, oral notices or complaints from any Person regarding such a Security Breach or incident, except in each case as would not have a Company Material Adverse Effect. None Except as would not have a Company Material Adverse Effect, (A) there is no unauthorized code in any of the Company Products and none of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) or entity regarding the Company IT Systems, any of the Group Companies’ Processing of Personal Data Data, or the Group Companies’ compliance with applicable Privacy and Security Requirements. Since Requirements and (B) since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have in place disaster recovery and security plans and procedures, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(e) The Except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards designed to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(g) To the extent required by applicable Privacy Law, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies have taken commercially reasonable measures designed to ensure all third party service providers, outsourcers, processors, or other third parties Processing Personal Data, in each case on behalf of the Group Companies, (i) use commercially reasonable measures designed to comply with applicable Privacy and Security Requirements; and (ii) use reasonable security measures with respect to Personal Data.
Appears in 2 contracts
Sources: Business Combination Agreement (Pathfinder Acquisition Corp), Business Combination Agreement (Pathfinder Acquisition Corp)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process and its Subsidiaries have at all times for the past two (2) years complied in all material respects with, and are currently in compliance in all material respects with, all applicable Privacy Laws, Privacy and Data Security Policies (as defined below) and contractual commitments relating to the Processing of Personal Data contrary to law(collectively, to each Group Company’s knowledgethe “Privacy Requirements”). The Company has safeguards in place that are sufficient and its Subsidiaries have implemented adequate written policies relating to protect the Processing of Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each Group Company extent required by applicable Law (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There are is no pending Proceedingspending, nor has there been for the past two (2) years, any Proceedings Proceeding against the Company or any Group Company of its Subsidiaries initiated by (i) any Person; , (ii) the ii)the United States Federal Trade Commission, any state attorney general or similar state official; , (iii) any other Governmental Entity Entity, foreign or domestic, or (iv) any regulatory or self-regulatory entity, in each case, alleging that any violation of any Privacy Requirement by the Company or its Subsidiaries with respect to any Processing of Personal Data by or on behalf of a Group the Company is in violation or any of any applicable Privacy Lawsits Subsidiaries.
(c) Since the Lookback Date, (i) there There has been no material breach of security resulting in unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of the Company or any Group Company of its Subsidiaries or, to the Company’s knowledge, any third party service provider of its contractors with regard to any Personal Data obtained from or on behalf of the Company or any Group Companyof its Subsidiaries, and (ii) or any unauthorized intrusions, breaches of security or other data security incidents with respect to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataSystems.
(d) Each Group The Company owns and its Subsidiaries own or has a have license to use the Company IT Systems as necessary to operate the business of each Group Business as currently conducted and the Company IT Systems operate and perform in a manner that permits the Company and its Subsidiaries to conduct the Business as currently conducted. The Group Companies have a sufficient number To the Company’s knowledge, none of license seats for all Software included in the Company IT SystemsSystems contain any worm, bomb, backdoor, clock, timer or other disabling device, code, design or routine that causes the Software of any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized person.
(e) The Group Companies are Company has taken commercially reasonable organizational, physical, administrative and technical measures required by Privacy Requirements, and consistent with standards prudent in the industry in which the Company operates, designed to protect the integrity, security and operations of the Company IT Systems. The Company and its Subsidiaries have implemented commercially reasonable procedures, including implementing data backup, disaster avoidance, recovery and business continuity procedures, and have been in compliance satisfied the requirements of applicable Privacy Laws in all material respects with all applicable Privacy respects, designed to detect data security incidents and Security Requirements since the Lookback Dateto protect Personal Data against loss and against unauthorized access, use, modification, disclosure or other misuse.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security consummation of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorstransactions contemplated hereby or pursuant to any Ancillary Document will not violate any applicable Privacy Requirements.
(g) There have not been any Proceedings related to any unauthorized intrusions, breaches of security or other data security incidents, or any violations of any Privacy Requirements, that have been asserted against the Company or any of its Subsidiaries and, to the Company’s knowledge, neither the Company nor any of its Subsidiaries has received any information relating to, or notice of any Proceedings with respect to, any alleged violations by the Company or any of its Subsidiaries of any Privacy Requirements.
Appears in 2 contracts
Sources: Business Combination Agreement (Strathspey Crown Holdings Group, LLC), Business Combination Agreement (Priveterra Acquisition Corp.)
Data Privacy and Security. (a) Each Except as set forth on Section 3.22(a) of the Company Disclosure Schedules, each Group Company does not knowingly collect or process has implemented written internal and external policies relating to the Processing of Personal Data contrary as and to lawthe extent required by applicable Privacy Law (“Privacy and Data Security Policies”). Except as set forth on Section 3.22(a) of the Company Disclosure Schedules, to for the past three years, each Group Company’s knowledge. The Company has safeguards in place that are sufficient at all times complied with all applicable Privacy Laws, the Privacy and Data Security Policies, and contractual obligations entered into by a Group Company relating to protect the Processing of Personal Data and confidential information in the Company’s possession any other applicable industry standards or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each requirements binding upon such Group Company (including with respect to employee matters) are in compliance with all collectively, the “Privacy and Security Requirements in all material respectsRequirements”).
(b) There are no The Company has not received notice of any pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity; or (iv) any regulatory state, federal, or self-regulatory entityinternational data protection authority, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy LawsRequirements.
(c) Since Except as set forth on Section 3.22(c) of the Lookback DateCompany Disclosure Schedules, for the past three years, (i) there has been no material unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to and/or any of the Company’s knowledge, any third party service provider on behalf providers of any Group Company, Company and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches any Company IT Systems under the control of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Each Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented has taken commercially reasonable physical, technical and administrative safeguards steps to protect (i) the privacy, operation, confidentiality, integrity and security of all the Company IT Systems systems and (ii) personal data in the Group Company’s possession or control, or otherwise processed by the Group Company, from unauthorized, accidental or unlawful use, disclosure and modification.
(e) Each Group Company is, and at all times has been, in compliance with all legal requirements that are applicable to each Group Company’s business as presently conduct pertaining to sales, marketing, and electronic communications, including, without limitation, the U.S. CAN-SPAM Act, the U.S. Telephone Consumer Protection Act (TCPA), and the Fair Credit Reporting Act (FCRA).
(f) Each Group Company has reasonable procedures in place to ensure that the third parties with which such Group Company shares or transfers Personal Data are required to protect the confidentiality of the shared or transferred Personal Data in their possession compliance with all applicable Privacy Requirements. Each Group Company has contractual arrangements with such third parties that comply with all applicable Privacy Requirements to the extent applicable to the third party’s services, use, or control from unauthorized access by any Person, including each processing of the Group Companies’ employees and contractorsPersonal Data.
Appears in 2 contracts
Sources: Business Combination Agreement (Digerati Technologies, Inc.), Business Combination Agreement (Minority Equality Opportunities Acquisition Inc.)
Data Privacy and Security. (a) Each The Group Companies comply with, and have at all times since January 1, 2017 complied with, all Data Protection Laws applicable to the Group Companies or to the conduct of the Business, except for noncompliance that would not reasonably be expected to have a Company does ▇▇▇▇▇ ▇▇▇▇▇▇▇▇ Adverse Effect. Except as would not knowingly collect have, or process would not reasonably be expected to have, individually or in the aggregate, a Company ▇▇▇▇▇ ▇▇▇▇▇▇▇▇ Adverse Effect, none of the Group Companies has used, disclosed, transferred, or otherwise processed any Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place any manner that are sufficient to protect Personal violates any Data and confidential information in Protection Law or is inconsistent with the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation terms of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsany Material Contract.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claimssubpoenas, demands, inquiries or other notices, including a notice of investigation, notices from any Person (including governmental Authority investigating, inquiring into, or otherwise relating to any Governmental Entity actual or self-regulatory authority) regarding potential violation of any Data Protection Law and, to the Knowledge of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback DateSeller, none of the Group Companies have provided is under investigation by any governmental Authority for any actual or have potential violation of any Data Protection Law.
(c) No notice, complaint, claim, enforcement action, or litigation of any kind has been obligated served on, or to provide notice the Knowledge of the Seller, initiated against the Group Companies under any Privacy applicable Data Protection Law.
(d) Except as set forth on Schedule 4.19(d), each of the Group Companies complies in all material respects with the terms of all published and Security Requirements posted policies, procedures, and notices of the Group Companies relating to regarding any Security Breach its collection, use, or unauthorized access to or use disclosure of any Company IT System or Personal Data.
(de) Each Group Company owns or has a license to use of the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance has taken commercially reasonable steps, compliant in all material respects with all applicable Privacy Data Protection Laws and Security Requirements since Material Contracts to protect the Lookback Dateoperation, confidentiality, integrity, and security of the Group Companies’ software, systems, and websites that are involved in the collection and/or processing of Personal Data.
(f) The Group Companies have implemented reasonable physicalExcept as would not have, technical and administrative safeguards or would not reasonably be expected to protect have, individually or in the privacyaggregate, operationa Company ▇▇▇▇▇ ▇▇▇▇▇▇▇▇ Adverse Effect, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each none of the Group Companies’ employees and contractorsCompanies has experienced any security breaches of Personal Data. To the Knowledge of the Seller, there are no pending or expected complaints, actions, fines, or other penalties facing the Group Companies in connection with any data security breaches.
Appears in 2 contracts
Sources: Share Exchange Agreement (Legacy Acquisition Corp.), Share Exchange Agreement (Legacy Acquisition Corp.)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or has administrative, technical and physical safeguards (including monitoring compliance with such safeguards) to protect the confidentiality, privacy and security of Personal Information and the systems, technology and networks that process Personal Data contrary to law, to each Group Company’s knowledgeInformation (the “Company Information Security”). The Company has safeguards in place that are sufficient produced to protect Personal Data the Purchaser true, correct and confidential information in complete copies of all written policies and procedures related to the Company Information Security. Each of the Company’s possession or control from unauthorized access by third Persons and employees has received appropriate training on the Company Information Security relevant to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectssuch employee’s role.
(b) There are no pending Proceedings, nor The Company has there been any Proceedings against any Group Company initiated by not experienced: (i) any Personunauthorized processing of Personal Information in the possession, custody or control of any of the Company; or (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing unauthorized processing by a third party of Personal Data by Information processed for or on behalf of the Company. The Company has not knowingly acted in a Group Company manner, is in violation not aware of any applicable Privacy Lawsincident or by the exercise or reasonable diligence would not be aware of any incident that would trigger an obligation to notify any person or Governmental Authority under any Laws or Contract.
(c) Since the Lookback Date, The Company is in compliance with and has complied with (i) there has been no material unauthorized access, use, acquisition or disclosure of all Laws related to Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and Information; (ii) all policies, procedures, processes, statements or notices related to Personal Information to the Company’s knowledgeextent such policies, there have been no unauthorized intrusions into procedures, processes, statements or Security Breaches of any Group Company systems networks, communication equipment notices are legally binding or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date give rise to legally-enforceable duties; and none of the Group Companies is aware of any written or, (iii) each Contract related to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person processing (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable “Privacy and Security Legal Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data”).
(d) Each Group The Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been either transmits Personal Information across jurisdictional borders in compliance in all material respects with all applicable Privacy Legal Requirements or processes Personal Information exclusively in the same jurisdiction as each data subject to which it relates resides.
(e) The Company has entered into written agreements with each third-party service provider, vendor and Security Requirements since business partner that processes Personal Information, such as payment card processors, advertising and marketing agencies, cloud storage vendors and outsourced technology or human resource functions, (collectively, “Data Related Vendors”) containing commercially reasonable provisions for data privacy and security. The Company has taken reasonable steps to select and retain only those Data Related Vendors that are capable of maintaining the Lookback Dateconfidentiality, privacy and security of the Personal Information that they process on behalf of the Company.
(f) The Group Companies have implemented reasonable physicalNo Person has commenced or threatened within the past five (5) years any Action or other written complaint, technical and administrative safeguards audit, proceeding, claim or investigation arising from or relating to protect the privacyprocessing by, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession for or control from unauthorized access by any Person, including each on behalf of the Group Companies’ employees Company.
(g) The execution, delivery and contractorsperformance of this Agreement and the consummation of the transactions contemplated herein shall not cause, constitute or result in a breach or violation any Privacy Legal Requirement, any policy, procedure, process, statement or notice of the Company as it currently exists or as it existed at any time during which any Personal Information was processed by or on behalf of the Company.
Appears in 2 contracts
Sources: Arrangement Agreement (Hecla Mining Co/De/), Arrangement Agreement (Klondex Mines LTD)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process Personal Data contrary to lawand its Subsidiaries and, to each Group the Knowledge of the Company, its Data Partners, comply and, within the last five years, have complied in all material respects with all Privacy Laws, Company Privacy Policies and Contracts relating to the processing, privacy and security of Personal Information (collectively, the “Company Privacy Commitments”), including compliance with respect to (i) Personal Information of Company’s knowledgewebsite visitors, customers or representatives of Company customers, the Company’s or its Subsidiaries’ own employees, or any other individual whose Personal Information is processed by the Company or its Subsidiaries; and (ii) the sending of solicited or unsolicited electronic or telephonic communications, including via email, text message or phone call. The Company has safeguards in place that are sufficient to protect and its Subsidiaries have implemented and maintained processes for identifying and redacting any Personal Data and confidential information Information contained in the Company’s possession or control from unauthorized access Spaces created by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsPlatform.
(b) There are no pending ProceedingsNeither the execution, delivery and performance of this Agreement by the Company nor has there been any Proceedings against any Group the consummation by the Company initiated by of the transactions contemplated hereby will (i) trigger or require any notices to or consents from any Person; (ii) the United States Federal Trade Commission, violate any state attorney general Company Privacy Commitments; or similar state official; (iii) give rise to any right of termination or other Governmental Entity right to impair or limit the Company’s or its Subsidiaries’ right to own and process any Personal Information used in or necessary for the operation of the business of the Company or its Subsidiaries. Since July 21, 2021, the Company and its Subsidiaries (ivA) any regulatory or self-regulatory entityhave, in each caseall material respects, alleging that any Processing implemented and maintain complete, accurate and up to date records of responses to requests from individuals requesting access, rectification or deletion of Personal Data by Information or on behalf other exercise of a Group rights under Company is in violation Privacy Commitments and (B) have responded to all requests from individuals requesting access, rectification, deletion or other exercise of any applicable rights under Privacy Laws, in the time period and in accordance in all material respects with the other requirements of Company Privacy Commitments.
(c) Since All Personal Information processed by the Lookback Date, (i) there Company or its Subsidiaries has been no collected fairly and lawfully (including through the provision of information notices and other disclosures (in the Company Privacy Policies or otherwise) and the collection of valid consent where required) and can be used legitimately in the manner used by the Company without breaching any Company Privacy Commitments. The Company and its Subsidiaries have, as of the date hereof and since July 21, 2021, posted and prominently made available on its websites, mobile applications and other mechanisms through which the Company or its Subsidiaries collects Personal Information, a Company Privacy Policy in conformance in all material unauthorized accessrespects with Privacy Laws. All Company Privacy Policies published by the Company are and, usesince July 21, acquisition or disclosure 2021, have, in all material respects, been accurate, complete and consistent with the actual practices of the Company and its Subsidiaries with respect to the processing of Personal DataInformation. As of the date hereof, no disclosure or confidential business information representation made or contained in any Company Privacy Policy published by the possession Company has been intentionally inaccurate, misleading, deceptive or control in violation of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and Privacy Laws (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced including by containing any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataomission).
(d) Each Group The Company owns and its Subsidiaries have in place written Contracts with all of their customers regarding the Company’s or has its Subsidiaries’ processing of Personal Information on behalf of such customers. Such Contracts include written obligations that comply with the requirements of Privacy Laws in relation to the Company’s and its Subsidiaries’ processing and protection of Personal Information. When acting as a license to use Data Processor on behalf of customers, the Company IT Systems as necessary and its Subsidiaries do not process Personal Information for any purpose except on the instruction of the customer (unless required to operate do so by applicable Law). Neither the business Company nor its Subsidiaries have transferred or permitted the transfer of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included Personal Information originating in the European Economic Area (“EEA”) or United Kingdom (“UK”) to outside the EEA or UK (as applicable), or otherwise across jurisdictional borders, except where such transfers have complied with the requirements of the Company IT SystemsPrivacy Commitments and with reasonable safeguards in place for such transfer.
(e) The Group Companies Where the Company or its Subsidiaries use a Data Partner to process Personal Information or otherwise share or disclose Personal Information with such Data Partner, there is in existence a Contract. Such Contract with the Data Partner includes written obligations in relation to the processing and protection of Personal Information and has agreed to comply with those obligations in a manner sufficient for the Company’s and its Subsidiaries’ compliance with Company Privacy Commitments, including where applicable, obligations for any party acting as a Data Processor (as defined under the Privacy Laws) to act only on the instructions of the Data Controller (as defined under the Privacy Laws) and such other terms as are and have been in compliance in all material respects with all applicable required under Privacy and Security Requirements since Laws. To the Lookback DateKnowledge of the Company, no Data Partner has breached any such Contracts.
(f) The Group Companies Company and its Subsidiaries have, and have required all Data Partners to have, implemented reasonable physicaladministrative, physical and technical and administrative safeguards to protect and maintain the privacy, operation, confidentiality, integrity integrity, availability and security of Personal Information and any information technology systems owned by the Company or its Subsidiaries against any accidental, unlawful or unauthorized use, access, disclosure, modification, destruction, loss, or compromise or other processing (a “Security Incident”). The Company and its Subsidiaries use, and have at all times used, reliable methods designed to ensure the correct identity of the users of those with access to any information technology systems owned by the Company or its Subsidiaries, and have used reliable measures designed to protect the security and integrity of transactions executed through the IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorsCompany or its Subsidiaries.
(g) In relation to any Security Incident and/or violation of Company Privacy Commitments, neither the Company, any Subsidiary, nor to the Knowledge of the Company, as of the date hereof, any Data Partner has: (i) notified in writing, or been required to notify in writing, any customer, consumer, employee, Governmental Authority or other Person or (ii) received any written notice, inquiry, request, claim, complaint, correspondence or other communication from, or been the subject of any investigation or enforcement action by, any Governmental Authority or other Person. To the Knowledge of the Company, as of the date hereof, there are no facts or circumstances that would give rise to the occurrence of (i) or (ii).
Appears in 2 contracts
Sources: Merger Agreement (Matterport, Inc./De), Merger Agreement (Matterport, Inc./De)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards and its Subsidiaries have developed, implemented and maintained a written data protection, data privacy and cybersecurity program (the “Data Protection Program”) that is in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in material compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since Requirements. To the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure knowledge of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Companysince January 1, 2019, the Company and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies its Subsidiaries have not experienced any material successful unauthorized access toSecurity Incident. Since January 1, use or modification of2019, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written no Person has brought, or, to the knowledge of the Company, oral notices threatened in writing to bring, any Action against the Company or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing its Subsidiaries in relation to any actual or alleged Security Incident or violation or breach of Personal Data or compliance with any applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataRequirement.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(eb) The Group Companies are Company and have been in compliance its Subsidiaries have, since January 1, 2019, complied in all material respects with all applicable Privacy Requirements with respect to the Processing of Company PII. The Company and Security its Subsidiaries are not and, since January 1, 2019, have not been subject to a Governmental Order of, or have received a written notice from, a Governmental Authority regarding actual or alleged non-compliance with or violation of any applicable Privacy Requirement. The Company and its Subsidiaries have taken commercially reasonable steps to ensure the reliability of their employees, representatives, consultants, contractors and agents that have access to Company PII, to train such individuals on all applicable Privacy Requirements since and to ensure that all such employees, representatives, consultants, contractors and agents with the Lookback Dateright to access such Company PII are under written obligations of confidentiality with respect to such Company PII.
(fc) The Group Companies have implemented reasonable physicalTo the knowledge of the Company, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group CompaniesCompany’s and its Subsidiaries’ employees third-party data suppliers, vendors, and contractorspartners that Process any Company PII on behalf of the Company or its Subsidiaries are in compliance in all material respects with applicable Privacy Requirements and there has been no material unauthorized or illegal Processing, or other material breach, violation or default (or event that, with or without the giving of notice or lapse of time, would constitute a material breach, violation or default) by any such supplier, vendor or other partner in connection with the Processing of Company PII. To the knowledge of the Company, no circumstances have arisen in which applicable Privacy Requirements would require the Company or its Subsidiaries to notify any Governmental Authority or affected individual of any Security Incident.
(d) The consummation of the Transactions will not materially breach any applicable Privacy Requirement.
Appears in 2 contracts
Sources: Merger Agreement (Highland Transcend Partners I Corp.), Merger Agreement (Highland Transcend Partners I Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data There is (and confidential information in since the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation date of the businesses incorporation of each Group Company (including with respect there has been) no material Proceeding pending or, to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedingsthe Company’s knowledge, nor has there been any Proceedings threatened against or involving any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iiiii) any other Governmental Entity Entity, foreign or domestic or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Group Company is or was in violation of any applicable Privacy Lawsand Security Requirements.
(cb) Since the Lookback DateJanuary 1, 2018, (i) there has been no material unauthorized accessSecurity Incidents with respect to any Company IT Systems, use, acquisition or disclosure of Personal Data, or Company Products or otherwise related to the business of any Group Company (including, to the Company’s knowledge, prior to each Group Company’s ownership of its business), (ii) to the Company’s knowledge there has been no unauthorized access to, or use, disclosure, or Processing of Personal Data or any trade secrets, know-how or confidential business information of or in the possession or control of any Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group Company, and (iiiii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware has notified or been required to notify any Person of any written or(A) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach (B) other unauthorized or incident. None of the Group Companies has received any written complaintsunlawful access to, claimsor use, demands, inquiries disclosure or other noticesProcessing of, including a notice of investigationPersonal Data, from any Person (including any Governmental Entity except, in each case, as is not and would not reasonably be excepted to be, individually or self-regulatory authority) regarding any of in the aggregate, material to the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Datataken as a whole.
(dc) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented taken reasonable physical, technical and administrative safeguards precautions to protect the privacy, operation, confidentiality, integrity and security of all the Company IT Systems and Personal Data in their possession all information stored or control contained therein or transmitted thereby from any loss, theft, or unauthorized access disclosure, use, access, interruption or modification by any Person. All Company IT Systems are (i) free from any Malicious Code, including material defect, bug or programming, design or documentation error and (ii) in sufficiently good working condition to effectively perform all material information technology operations necessary for the operation of the business of the Group Companies (except for ordinary wear and tear). Since January 1, 2018, there have not been any material failures, breakdowns or continued substandard performance of any Company IT Systems that have caused a material failure or disruption of the Company IT Systems, including, to the Company’s knowledge, prior to each Group Company’s ownership of its business. The Group Companies have implemented, maintained and tested adequate and commercially reasonable disaster recovery procedures and facilities for their respective businesses.
(d) The Group Companies (i) engage and have engaged in, directly or indirectly, Data Processing only with respect to such Data as they are authorized to so engage (or to cause such Processing, as applicable) by Law and Contract, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, and (ii) have implemented reasonable safeguards designed to prevent unauthorized use or disclosure of such Data. The Group Companies have, with respect to all such Data that is subjected to any Processing directly or indirectly in connection with the business of the Group Companies’ employees and contractors, all rights necessary to conduct the operation of their respective businesses as then-currently conducted, in all material respects.
Appears in 2 contracts
Sources: Business Combination Agreement (Bannix Acquisition Corp.), Business Combination Agreement (Bannix Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards and its Subsidiaries have, in place that are sufficient all material respects, implemented and maintain commercially reasonable data backup, system redundancy, and disaster avoidance and recovery plans and procedures, as well as commercially reasonable information security plans, procedures and arrangements designed to protect Personal Data and confidential preserve the availability, integrity, security, confidentiality and operation of the IT Systems (including all information stored or contained therein or transmitted thereby) against any unauthorized use, access, interruption, modification or corruption. Since January 1, 2019, there have been no data breaches or security incidents with respect to the IT Systems that resulted in any unauthorized access to or use, disclosure, modification or corruption of any information stored or contained therein, or resulted in the Company’s possession exertion of third-party control over any of the IT Systems, except those that (i) have been remedied without any material cost or control from unauthorized access by third Persons material liability to the Company or any of its Subsidiaries or the duty to notify any other Person, and (ii) did not cause a material disruption to ensure that the IT Systems or otherwise have a material impact on the operation of the businesses business of each Group the Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsor any its Subsidiaries.
(b) There are no pending ProceedingsSince January 1, nor has there been any Proceedings against any Group 2019, the Company initiated by and its Subsidiaries (i) have posted a privacy policy on the Company’s website regarding the collection, use, disclosure, disposal, maintenance and transmission of any Person; Personal Information of visitors to the website, (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company orhave and, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge Knowledge of the Company, oral notices all affiliates, vendors, or complaints from any Person regarding such a Security Breach or incident. None processors, with respect to their processing of Personal Information on behalf of the Group Companies has received any written complaintsCompany and its Subsidiaries, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy Laws and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity Orders concerning data protection or information privacy and security and (iii) have complied in all material respects with their posted privacy policies, and contractual requirements pertaining to data protection or information privacy and security. Since January 1, 2019, to the Knowledge of all the Company, neither the Company IT Systems nor any of its Subsidiaries (i) has been required to notify a Governmental Authority or any other Person in relation to a security incident or any applicable Law or Order relating to data protection or information privacy and Personal Data in their possession security, (ii) has received any written notice from any Governmental Authority alleging a violation of any applicable Laws or control from unauthorized access Orders concerning data protection or information privacy and security and (iii) to the Knowledge of the Company, there is no pending investigation by any Person, including each Governmental Authority of the Group Companies’ employees and contractorsCompany or any of its Subsidiaries relating to such Laws or Orders.
Appears in 2 contracts
Sources: Merger Agreement (Domtar CORP), Merger Agreement (Resolute Forest Products Inc.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process has since January 1, 2017 (i) complied in all material respects with all applicable Privacy Laws and published interpretations by Governmental Entities and supervisory authorities of such Privacy Laws. Each Group Company has implemented adequate written policies relating to the Processing of Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each Group Company extent required by applicable Law (including with respect to employee matters“Privacy and Data Security Policies”) are and has complied in compliance all material respects with all Privacy and Data Security Requirements Policies, including (A) all privacy policies and similar disclosures published on each web site or mobile app of the Group Company or otherwise communicated in all material respectswriting to users of any such web site or mobile app and other third parties, (B) any notice to or consent from the provider or data subject of Personal Data, and (C) any contractual commitment made by the Group Company with respect to such Personal Data.
(b) There are is no pending Proceedingspending, nor has there been any material Proceedings against any Group Company Company, and, to the Company’s knowledge, there are no facts or circumstances which could reasonably serve as the basis for any such material Proceedings, initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity, foreign or domestic; or (iv) any supervisory authority of any member state of the European Union or the United Kingdom, or any regulatory or self-regulatory entity, in each case, entity alleging that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Policies.
(c) Since the Lookback Date, (i) Since January 1, 2018, to the knowledge of the Company, there has been no material personal data breaches (as defined in the GDPR), unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group Company or, and any of its contractors or service providers with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group Company, Company and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the systems. Each Group Companies’ business. The Group Companies have not experienced any Company maintains a commercially reasonable data breach response plan that is designed to ensure material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since Laws in the Lookback Date, none event of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataa personal data breach.
(d) Each Except as set forth on Section 3.21(d) of the Company Disclosure Schedules, each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a Company IT Systems are sufficient number of license seats for all Software included in to operate the Business and the Company owns or has valid and enforceable rights to use the Company IT Systems. The Company has commercially reasonable backup and disaster recovery plans, procedures and facilities for the business of the Group Companies, and has taken and implemented commercially reasonable technical, organizational and security measures to safeguard the Company IT Systems and all data and information processed on the Company IT Systems. To the knowledge of the Company, there have been no unauthorized intrusions or breaches of the security of the Company IT Systems or infections by viruses or other harmful code. The Company IT Systems operate in a reasonable manner sufficient for the needs of the business of the Group Companies as currently conducted, and there has not been any material known malfunction with the Company IT Systems that has not been remedied or replaced in all material respects, or any material unplanned downtime or material service interruption.
(e) The Each Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
Company has (fa) The Group Companies have implemented taken commercially reasonable organizational, physical, administrative and technical measures required by Privacy Laws and administrative safeguards consistent with commercially reasonable industry standards in the industry in which the Group Company operates, any existing contractual commitment made by the Group Company that is applicable to Personal Data and the Group Company's information security program to protect (i) the privacyintegrity, operationsecurity and operations of the Group Company's information technology systems, confidentiality, integrity and security of all (ii) the data owned by the Group Company IT Systems and Personal Data in their possession against data security incidents or control from other misuse. The Group Company has (a) implemented commercially reasonable procedures, satisfying the requirements of applicable Privacy Laws, to detect data security incidents; and (b) implemented and monitored compliance with commercially reasonable measures with respect to technical and physical security, to protect Personal Data against loss and against unauthorized access by any Personaccess, including each of the Group Companies’ employees and contractorsuse, modification, disclosure or other misuse.
Appears in 1 contract
Sources: Business Combination Agreement (Qell Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient at all times for the past three (3) years prior to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements date hereof complied in all material respectsrespects with all applicable Privacy Laws, Privacy and Data Security Policies (as defined below) and contractual commitments relating to the Processing of Personal Data (collectively, the “Privacy Requirements”). Except as set forth on Section 3.21(a) of the Company Disclosure Schedule, the Company has implemented adequate written policies relating to the Processing of Personal Data as and to the extent required by applicable Law (“Privacy and Data Security Policies”).
(b) There are is no pending Proceedingspending, nor has there been for the past three (3) years prior to the date hereof, any Proceedings material Proceeding against any Group the Company initiated by (i) any Person; , (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iii) any other Governmental Entity Entity, foreign or domestic, or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group the Company is in violation of any applicable Privacy Requirements or Privacy Laws.
(c) Since For the Lookback Datepast three (3) years prior to the date hereof, the Company has implemented and maintained, consistent with practices reasonable for similarly-situated companies in the industry in which the Company operates and its respective obligations to third parties, reasonable security and other measures designed to be adequate to protect the Company IT Systems used by the Company to store, process or transmit Intellectual Property Rights of the Company or Personal Data from loss, theft, unauthorized access, use, disclosure or modification, including reasonable measures (no less than reasonable for similarly situated companies in the industry in which the Company operates) designed to be adequate to (i) secure Company IT Systems from unauthorized access and use by any Person; (ii) defend Company IT Systems against Malicious Code, denial of service attacks, distributed denial of service attacks, hacking attempts, and like attacks and activities by any other Person; and (iii) ensure the continued and uninterrupted operation of Company IT Systems, including by employing reasonable security, maintenance, disaster recovery, redundancy, backup, archiving, and anti-virus systems (no less than reasonable for similarly-situated companies in the industry in which the Company operates) designed to be adequate to maintain and protect the performance, confidentiality, integrity and security of all Company IT Systems (and all software, information and data stored or contained therein or transmitted thereby). To the Company’s knowledge, none of the Company IT Systems contain any (A) devices, errors, contaminants or effects that materially disrupt or adversely affect the functionality of any Company IT Systems (or any software stored or contained therein), nor enable or assist any Person to access any Company IT Systems (or any software, information or data stored or contained therein or transmitted thereby) without authorization, or (B) Malicious Code.
(d) For the past three (3) years prior to the date hereof, there has been no material breach of security resulting in unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group the Company or, to the Company’s knowledge, any third party service provider of its contractors with regard to any Personal Data obtained from or on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach material unauthorized intrusions or incident. None breaches of security into the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataCompany’s systems.
(de) Each Group The Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company Business as currently conducted. The Group Companies have a sufficient number To the Company’s knowledge, none of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects Systems contain any worm, bomb, backdoor, clock, timer or other disabling device, code, design or routine that causes the Software of any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with all applicable Privacy and Security Requirements since the Lookback Datepassage of time or upon command by any unauthorized person.
(f) Neither the Company nor, to the Company’s knowledge, any third party acting at the direction or authorization of the Company has paid (i) any perpetrator of any data breach incident or cyber-attack; or (ii) any third party with actual or alleged information about a data breach incident or cyber-attack, in each case, pursuant to a request for payment from or on behalf of such perpetrator or other third party.
(g) The Group Companies have implemented Company has taken commercially reasonable organizational, physical, administrative and technical measures required by Privacy Requirements, and administrative safeguards consistent with standards typical for similarly-situated companies in the industry in which the Company operates, designed to protect the privacyintegrity, operation, confidentiality, integrity security and security operations of all the Company IT Systems Systems. The Company has implemented commercially reasonable procedures, satisfying the requirements of applicable Privacy Laws in all material respects, designed to detect data security incidents and to protect Personal Data against loss and against unauthorized access, use, modification, disclosure or other misuse.
(h) There have not been any Proceedings related to any data security incidents or any violations of any Privacy Requirements that have been asserted in their possession writing against the Company and, to the Company’s knowledge, the Company has not received any written correspondence relating to, or control from unauthorized access written notice of any Proceedings with respect to, alleged violations by the Company of any Person, including each of the Group Companies’ employees and contractorsPrivacy Requirements.
Appears in 1 contract
Sources: Business Combination Agreement (Phoenix Biotech Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company and its Subsidiaries complies, and during the past three (3) years has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons complied, and to ensure that the operation Knowledge of the businesses of Company each Group Company Data Processor complies and during the past three (including with respect to employee matters3) are in compliance years has complied, with all Privacy and Security Requirements and all Data Requirements. The Company’s and its Subsidiaries’ processing of Personal Information or Personal Data and Company Data is and, during the past three (3) years, has been in compliance with, applicable Data Requirements. Neither the Company nor any of its Subsidiaries permits the processing of Personal Information or Personal Data outside, and has not transferred Personal Information or Personal Data to a country or territory outside, of the United States, the European Economic Area or the United Kingdom in material breach of the Data Protection Laws. For the avoidance of doubt, all material respectsdisclosures or transfers of Personal Data have complied with all applicable requirements set out in the Data Protection Laws. From the date which is three (3) years prior to the date hereof through the Closing Date, neither the Company, its Subsidiaries nor the Knowledge of the Company, any other Person has received notice of any complaint, investigation, correspondence, communication or other inquiry from any Governmental Authority or data subject regarding any actual, alleged or possible violation of, or failure to comply with, any Data Requirements or any Privacy and Security Requirement by the Company, its Subsidiaries or, any Data Processor. There is not currently pending and there has not been within the last three (3) years any third-party claim against any member of the Company nor its Subsidiaries alleging any violation of, or failure to comply with, any Privacy and Security Requirement. If Seller participates in such cross-border data transfers, Seller has entered into a written contract with each Data Processor that is used by Seller and, where Seller acts as a processor, a written contract has been executed with any data controller, in each case that complies with the requirements of the Data Protection Laws. Neither Seller nor any of its Data Processors is in violation of any restrictions on the transfer of data across national borders that are contained in any contracts or agreements to which Seller is bound.
(b) There are no pending ProceedingsThe Company and each of its Subsidiaries has provided and complied with all requisite notices and obtained all required consents, nor has there been any Proceedings against any Group and satisfied all other requirements necessary for the processing of Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general Data and Personal Information or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf the Company and/or its Subsidiaries as currently conducted. Neither the Company, its Subsidiaries, nor, to the Knowledge of a Group Company the Company, any of its Data Processors, is in violation of any applicable Privacy Lawsrestrictions on the transfer of data across national borders that are contained in any Data Agreement. During the past three (3) years, there has been no Security Incident, nor any material: (i) loss or theft of data, accidental or unlawful destruction, alteration, security breach, personal data breach or accidental or unauthorized access, disclosure or use relating to data (including Company Data) in the possession, custody or control of the Company or its Subsidiaries, or (ii) unintended or improper disclosure of any such data (including Company Data in the possession, custody or control of the Company, its Subsidiaries, or a contractor or agent in its provision of material services to the Company).
(c) Since The transactions to be consummated hereunder as of the Lookback DateClosing Date will not cause or constitute a breach or violation of any Data Requirements, privacy notice or any other Privacy and Security Requirement by the Company or its Subsidiaries.
(d) The Company, its Subsidiaries, and, to the Knowledge of the Company, its Data Processors each adhere to a privacy and information security program that (i) there has been no material unauthorized accessconsists of appropriate organizational, useadministrative, acquisition or disclosure physical and technical safeguards designed to safeguard the Company Systems, Company Data and the processing of Personal DataInformation or Personal Data against the unauthorized or unlawful processing of, or confidential business information in the possession accidental loss or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, damage and (ii) to the Company’s knowledgemeets relevant industry standards, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations all applicable requirements of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements, and all applicable requirements of applicable Law. Since Except as set forth on Schedule 3.25(d), the Lookback DateCompany and its Subsidiaries have employed industry standard encryption on Personal Information or Personal Data at rest and in transit, none of the Group Companies have provided and on all Company Systems, including on portable devices containing or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach transmitting confidential information or unauthorized access to or use of any Company IT System Personal Information or Personal Data.
(de) Each Group Within the past three (3) years, (i) no actual or suspected Security Incident has occurred (including any loss of confidentiality, integrity or availability) with respect to any Company owns or has a license to use Systems, nor the Company Systems of its Subsidiaries, or confidential information or Personal Information or Personal Data thereon, and no Person has, or is suspected to have obtained, used, accessed, disclosed, or otherwise processed any Personal Information or Personal Data or confidential information or Company Systems or the Company Systems of its Subsidiaries, including for any illegal, wrongful or unauthorized purpose; (ii) neither the Company nor any of its Subsidiaries have experienced any interruption or disruption to its IT Systems as necessary systems or to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in conducted by the Company IT and/or its Subsidiaries in connection with any event affecting Company Systems.
, and (eiii) The Group Companies are and no claims have been asserted or, to the Knowledge of the Company, threatened in compliance in all material respects with all applicable Privacy and Security Requirements since writing against the Lookback DateCompany or its Subsidiaries relating to data security, privacy, or the storage, transfer, use or processing of Company Data or Personal Information or Personal Data under any Data Agreements.
(f) The Group Companies have implemented reasonable physicalCompany Systems are sufficient for the Company’s and its Subsidiaries’ current operations (including as to capacity, technical scalability and administrative safeguards ability to protect process current volumes in a timely manner) and operate and perform in all material respects as required in connection with, the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each operation of the Group Companies’ employees business of the Company and/or its Subsidiaries as presently conducted. During the past three (3) years, there has been no material breach, intrusion, or unauthorized use of or access to any Company Systems, and contractors.the Company Systems have had no material errors or defects that have not been reasonably mitigated in all material respects, and contain no code designed to disrupt, disable, harm, distort or otherwise
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards delivered accurate and complete copies of all written policies and procedures maintained by Holdings or the Company currently in place effect or in effect at any time since August 22, 2013 that are sufficient relate to protect Personal Data privacy and confidential information in the Company’s possession personal data protection, including any such policies that relate to personal data from or control from unauthorized access by third about any representatives, customers, suppliers, service providers, or any other Persons and to ensure that the operation of the businesses of each Group (“Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsPolicies”).
(b) There are no pending ProceedingsEach of Holdings and the Company has complied in all material respects with, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is not in violation of of, and has not received any applicable Privacy Laws.
notice or other communication (c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company writing or, to the Company’s knowledge, in any third party service provider on behalf other manner) of any Group violation with respect to, any laws, contracts, Company Privacy Policies or any other commitments, obligations, or representations concerning privacy and personal data protection (“Company Privacy Obligations”). The consummation of the contemplated transactions will not violate any Company Privacy Obligation, or require Holdings or the Company to provide any notice to, or seek any consent or waiver from, any representative, customer, vendor, supplier, service provider, or other person under any Company Privacy Policy. To the Company’s knowledge, and no Company Privacy Obligations will impose any restrictions upon the Purchaser’s ability to use, possess, disclose, or transfer any personal data in the manner Holdings or the Company has used, possessed, disclosed, or transferred any personal data before the Closing. Neither Holdings nor the Company has received any notice or other communication (ii) in writing or, to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches in any other manner) of any Group claims or alleged claims that Holdings or the Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced has violated any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written orPrivacy Obligations and, to the knowledge Company’s knowledge, no Governmental Authority is investigating to determine whether Holdings or the Company has violated any Company Privacy Obligations. Holdings and the Company have collected, received, generated, used, processed, imported, exported, transferred, disclosed and disposed of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or all personally identifiable information in material compliance with all applicable Privacy Laws relating to data privacy.
(c) Holdings and Security Requirements. Since the Lookback DateCompany have stored, none of maintained, and transmitted all personally identifiable information, including, but not limited to, credit card related information, in compliance with (i) all data protection Laws, and (ii) all contractual obligations, including, but not limited to, obligations imposed upon Holdings or the Group Companies have provided or have been obligated to provide notice Company under any Privacy and Security Requirements agreement to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataprocess credit card transactions.
(d) Each Group Company owns or has a license to use Holdings and the Company IT Systems as necessary have taken commercially reasonable measures to operate protect all personally identifiable information against loss, or unauthorized access, use, modification, or acquisition. In the business context of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in credit card related information, Holdings and the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy the most recent Payment Card Industry (“PCI”) Data Security Standard (“DSS”). Holdings and Security Requirements since the Lookback Date.Company have completed an on-site report on compliance (“ROC”) from a qualified security assessor (“QSA”), or have completed a self-assessment questionnaire (“SAQ”) within the 12 months immediately preceding the date of this Agreement. The ROC and/or SAQ did not identify any areas of non-compliance with the PCI DSS. The Company is not aware of any facts or circumstances that would prevent a ROC or SAQ from currently being completed that indicates that there are no areas of non-compliance with the PCI DSS. 25
(fe) The Group Companies Holdings and the Company have implemented taken commercially reasonable physicalmeasures to detect and respond to security incidents involving any attempted or successful unauthorized access, technical and administrative safeguards use, disclosure, modification, or destruction of personally identifiable information. To the Company’s knowledge, no personally identifiable information, including, but not limited to, credit card related information, has been lost, stolen, hacked, violated or otherwise lawfully removed from the possession of Holdings or the Company, or has been revealed, acquired, accessed, or used by or disclosed to protect any person not authorized by the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorsCompany.
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company and each of its Subsidiaries has implemented commercially reasonable administrative and technical safeguards in place that are sufficient designed to protect the integrity, security and confidentiality of Personal Data and confidential information Information stored in the Company’s possession IT Systems. Except as would not, individually or control from in the aggregate, reasonably be expected to have a Company Material Adverse Effect, since January 1, 2022: (i) there have been no failures, breakdowns or other adverse events materially affecting any such IT Systems that have caused a material disruption or interruption to the conduct of the business of the Company or any of its Subsidiaries as presently conducted, and (ii) there have not been any incidents of unauthorized access by third Persons and to ensure that the operation or other security breaches of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsIT Systems.
(b) There are no pending ProceedingsThe Company and each Subsidiary has implemented and maintained commercially reasonable and appropriate technical and organizational safeguards designed to protect Personal Information and other confidential data in its possession or under its control against loss, nor has there been any Proceedings against any Group theft, misuse or unauthorized access, use, modification, alteration, destruction or disclosure and the Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging and its Subsidiaries have taken commercially reasonable steps to require that any Processing of third party with access to Personal Data Information collected by or on behalf of a Group the Company is or any Subsidiary has implemented and maintained the same. To the Company’s Knowledge, any third party that has provided Personal Information to the Company or any Subsidiary has done so in violation of compliance with applicable Data Protection Laws, including providing any notice and obtaining any consent required by applicable Privacy Data Protection Laws.
(c) Since the Lookback DateThe Company and each Subsidiary is, (i) there and has been no material unauthorized accessbeen, usein compliance with applicable Data Protection Requirements, acquisition except for any noncompliance that would not, individually or disclosure of Personal Data, or confidential business information in the possession aggregate, reasonably be expected to have a Company Material Adverse Effect. Except as would not, individually or control of any Group in the aggregate, reasonably be expected to have a Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledgeMaterial Adverse Effect, there have been no breaches, violations, outages, security incidents, unauthorized intrusions into uses, transfer, destruction, disclosures, losses, thefts, ▇▇▇▇▇▇ demands, alterations of or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written orto Personal Information maintained by, to the knowledge Knowledge of the Company, oral notices or complaints on behalf of the Company or any Subsidiary that would require notification of individuals, law enforcement or any Governmental Authority under any applicable Data Protection Law. Neither the Company nor any Subsidiary has received written notice of any claim or investigation or any other written communication (including from any Person regarding such a Security Breach Governmental Authority) that alleges that the Company or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or Subsidiary is not in compliance with applicable Privacy and Security Requirements. Since any Data Protection Laws, except as would not reasonably be expected to be material to the Lookback DateCompany, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Datataken as a whole.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Data Privacy and Security. (a) Each Group Except as would not be material to the Business, the Company does not knowingly collect and the Company Subsidiaries, and to the Knowledge of the Company, all vendors, processors, or process other third parties Processing Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession for or control from unauthorized access by third Persons and to ensure that the operation on behalf of the businesses of each Group Company (including with respect to employee matters) and the Company Subsidiaries, are and have been at all times in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) the terms and conditions of any and all of their own privacy policies and other external-facing policies or notices governing the use of Personal Data (each a “Company Privacy Policy”); and (ii) Privacy and Information Security Requirements ((i) and (ii) the “Company Privacy Commitments”). Except as would not be material to the Business, neither the execution, delivery or performance of this Agreement by the Company nor the consummation by the Company of the transactions contemplated hereby will (i) trigger or require any notices to or consents from any Person; (ii) the United States Federal Trade Commission, violate any state attorney general Company Privacy Commitments; or similar state official; (iii) give rise to any right of termination or other Governmental Entity right to impair or limit the Company’s or the Company Subsidiaries’ right to own and/or Process any Personal Data used in or necessary for the operation of the business of the Company or the Company Subsidiaries.
(ivb) any regulatory Except as would not be material to the Business, (i) the Company and the Company Subsidiaries have at all times posted and prominently made available on its websites, mobile applications, intranet, internal regulations, other mediums made accessible to individuals and other mechanisms through which the Company or self-regulatory entitythe Company Subsidiaries collect Personal Data, a Company Privacy Policy in conformance with Privacy and Information Security Requirements and have satisfied all other requirements necessary for their Processing of all Personal Data, (ii) all Company Privacy Policies are and have at all times been accurate, not misleading or deceptive (including by omission), consistent and complete with the actual practices of the Company and the Company Subsidiaries with respect to the processing of Personal Data, and (iii) the Company and the Company Subsidiaries have in place written Contracts with (A) all third parties who Process, store or otherwise handle Personal Data on behalf of the Company and the Company Subsidiaries, or that otherwise receive Personal Data from the Company and the Company Subsidiaries, and (B) all of their customers regarding the Company’s or the Company Subsidiaries’ Processing of Personal Data on behalf of such customers, in each case, alleging sufficient for the Company’s and the Company Subsidiaries’ compliance with Company Privacy Commitments and that any Processing of Personal Data by or on behalf of a Group Company is in violation of any obligate the other Persons to comply with all applicable Privacy Lawsand Information Security Requirements.
(c) Since The Company and the Lookback DateCompany Subsidiaries have used commercially reasonable efforts to implement administrative, physical and technical safeguards to (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in protect and maintain the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems Personal Data against any unauthorized use, access, disclosure, interruption, modification, destruction, comprise or corruption (a “Security Incident”); (ii) identify and address internal and external risks to the privacy and security of Personal Data in their possession or control from control; and (iii) provide immediate notification to the Company and/or the Company Subsidiaries in the case of Security Incident.
(d) Neither the Company nor the Company Subsidiaries have suffered a Security Incident with respect to any of the Personal Data Processed by or, to the Knowledge of the Company, on behalf of, the Company or the Company Subsidiaries. Except as would not be material to the Business, neither the Company nor the Company Subsidiaries have (i) been legally or contractually required to provide any notices to any Person in connection with an unauthorized access disclosure of Personal Data with respect to the operation of the business, or has done so even if not legally or contractually so required; or (ii) received any written complaints or notices to, or been subject to audits, proceedings, investigations or claims asserted with respect to, by any PersonPerson or Governmental Authority, including each (A) the Company’s or the Company Subsidiaries’ Processing of Personal Data in connection with the businesses of the Group Companies’ employees Company and contractorsthe Company Subsidiaries or (B) compliance with any Company Privacy Commitments and, to the Knowledge of the Company, there are no facts or circumstances in existence that can give rise to any such complaints, notices, audits, proceedings, investigations or claims.
Appears in 1 contract
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process and its Subsidiaries have at all times for the past two (2) years complied with, and are currently in compliance with, all applicable Privacy Laws, Privacy and Data Security Policies (as defined below) and contractual commitments relating to the Processing of Personal Data contrary to law(collectively, to each Group Company’s knowledgethe “Privacy Requirements”). The Company has safeguards in place that are sufficient and its Subsidiaries have implemented adequate written policies relating to protect the Processing of Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each Group Company extent required by applicable Law (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There are is no pending Proceedingspending, nor has there been for the past two (2) years, any Proceedings Proceeding against the Company or any Group Company of its Subsidiaries initiated by (i) any Person; , (ii) the ii)the United States Federal Trade Commission, any state attorney general or similar state official; , (iii) any other Governmental Entity Entity, foreign or domestic, or (iv) any regulatory or self-regulatory entity, in each case, alleging that any violation of any Privacy Requirement by the Company or its Subsidiaries with respect to any Processing of Personal Data by or on behalf of a Group the Company is in violation or any of any applicable Privacy Lawsits Subsidiaries.
(c) Since the Lookback Date, (i) there There has been no material breach of security resulting in unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of the Company or any Group Company of its Subsidiaries or, to the Company’s knowledge, any third party service provider of its contractors with regard to any Personal Data obtained from or on behalf of the Company or any Group Companyof its Subsidiaries, and (ii) or any unauthorized intrusions, breaches of security or other data security incidents with respect to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataSystems.
(d) Each Group The Company owns and its Subsidiaries own or has a have license to use the Company IT Systems as necessary to operate the business of each Group Business as currently conducted and the Company IT Systems operate and perform in a manner that permits the Company and its Subsidiaries to conduct the Business as currently conducted. The Group Companies have a sufficient number To the Company’s knowledge, none of license seats for all Software included in the Company IT SystemsSystems contain any worm, bomb, backdoor, clock, timer or other disabling device, code, design or routine that causes the Software of any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized person.
(e) The Group Companies are Company has taken commercially reasonable organizational, physical, administrative and technical measures required by Privacy Requirements, and consistent with standards prudent in the industry in which the Company operates, designed to protect the integrity, security and operations of the Company IT Systems. The Company and its Subsidiaries have implemented commercially reasonable procedures, including implementing data backup, disaster avoidance, recovery and business continuity procedures, and have been in compliance in all material respects with all satisfied the requirements of applicable Privacy Laws designed to detect data security incidents and Security Requirements since the Lookback Dateto protect Personal Data against loss and against unauthorized access, use, modification, disclosure or other misuse.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security consummation of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorstransactions contemplated hereby or pursuant to any Ancillary Document will not violate any applicable Privacy Requirements.
(g) There have not been any Proceedings related to any unauthorized intrusions, breaches of security or other data security incidents, or any violations of any Privacy Requirements, that have been asserted against the Company or any of its Subsidiaries and, to the Company’s knowledge, neither the Company nor any of its Subsidiaries has received any information relating to, or notice of any Proceedings with respect to, any alleged violations by the Company or any of its Subsidiaries of any Privacy Requirements.
Appears in 1 contract
Sources: Business Combination Agreement (Redwoods Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation each of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company orits Subsidiaries and, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge Knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaintsall vendors, claims, demands, inquiries partners or other noticesthird parties that Process Personal Information on behalf of, including a notice of investigationor that otherwise share Personal Information with, from any Person (including any Governmental Entity the Company or self-regulatory authority) regarding any of its Subsidiaries (in the Group Companies’ Processing case of Personal Data or compliance with applicable Privacy such vendors, partners, and Security Requirements. Since the Lookback Dateother third parties, none of the Group Companies have provided or have been obligated relating to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business or any of each Group its Subsidiaries) (“Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are Data Partners”), are, and have been at all times during the past three (3) years been, in compliance in all material respects with all applicable (i) Privacy Laws, (ii) the Company’s and Security Requirements since its Subsidiaries’ policies, representations, and notices, (iii) the Lookback Daterequirements of any industry standard or self-regulatory organization by which the Company or any of its Subsidiaries is bound, and (iv) contractual commitments by which the Company or any of its Subsidiaries is bound, in each case of (ii) – (iv), relating to privacy, data protection, security, or the Processing of Company Data (collectively, (i) – (iv), “Company Privacy Obligations”). The Company and each of its Subsidiaries has at all applicable times during the past three (3) years provided all material notices and obtained all material authorizations, consents, and rights required under Company Privacy Obligations to Process Company Data as Processed by or for the Company or any of its Subsidiaries.
(fb) The Group Companies have Company and each of its Subsidiaries has implemented and maintained reasonable and appropriate physical, technical technical, and administrative safeguards organizational measures designed to protect the Company IT Assets and Company Data. There has been no (i) material security incident, breach, or successful ransomware, denial of access attack, denial of service attack, hacking, or similar event with respect to any Company IT Asset, nor (ii) any material unauthorized, accidental, or unlawful access to, or destruction, loss, alteration disclosure, or other Processing of, Company Data (each, in the case of (i) and (ii), a “Company Security Incident”). None of the Company or any of its Subsidiaries, nor, to the Knowledge of the Company, the Company Data Partners, has made, or been required to make, any disclosure or notification to any Person under any Company Privacy Obligation in connection with any Company Security Incident. None of the Company or any of its Subsidiaries has received any notification from any Governmental Authority or other Person of any material Action relating to the data privacy, operationdata security, confidentialitydata protection, integrity and security or the Processing of all Company IT Systems and Personal Data in their possession Data, or control from unauthorized access alleging any violation of any Company Privacy Obligation. To the Knowledge of the Company, there has never been any audit, investigation or enforcement action (including any fines or other sanctions) by any Person, including each Governmental Authority or other Person relating to any Company Security Incident or violation of the Group Companies’ employees and contractorsany Company Privacy Obligation.
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect involved in the collection or process Processing of Personal Data contrary has implemented and, where applicable, posted written privacy notices relating to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect the Processing of Personal Data to the extent required by applicable Privacy Laws (“Privacy and confidential information in Data Security Policies”) and is, and since the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are Lookback Date, has been, in compliance with all Privacy and Security Requirements in all material respectsrespects with such Privacy and Data Security Policies.
(b) There To the Company’s knowledge, there are no pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory entity or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any Privacy and Security Requirements. The Group Companies do not engage in the sale, as such term is defined by applicable Privacy Lawslaw, of Personal Data.
(c) Since the Lookback Date, to the Company’s knowledge (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third third-party service provider acting on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment IT Systems or other technology necessary for the operations of the Group Companies’ business, except in the case of clauses (i) and (ii), as would not have a Company Material Adverse Effect. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company’s knowledge, oral notices or complaints from any Person regarding such a Security Breach or incident, except in each case as would not have a Company Material Adverse Effect. None Except as would not have a Company Material Adverse Effect, (A) there is no unauthorized code in any of the Company Products and none of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) or entity regarding the Company IT Systems, any of the Group Companies’ Processing of Personal Data Data, or the Group Companies’ compliance with applicable Privacy and Security Requirements. Since Requirements and (B) since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have in place disaster recovery and security plans and procedures, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(e) The Except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards designed to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(g) To the extent required by applicable Privacy Law, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies have taken commercially reasonable measures designed to ensure all third-party service providers, outsourcers, processors, or other third parties Processing Personal Data, in each case on behalf of the Group Companies, (i) use commercially reasonable measures designed to comply with applicable Privacy and Security Requirements; and (ii) use reasonable security measures with respect to Personal Data.
Appears in 1 contract
Sources: Business Combination Agreement (Pathfinder Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company Group has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with at all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance times complied in all material respects with all applicable Privacy and Data Security Requirements since Obligations. Neither (i) the Lookback Dateexecution, delivery or performance of this Agreement or any other agreements referred to in this Agreement, nor (ii) the consummation of any of the Transactions, will result in violation of any applicable Privacy and Data Security Obligations or any Privacy Policy.
(b) Without limiting the foregoing: (i) to the extent required by any Privacy and Data Security Obligations (A) the Company Group has maintained and posted Privacy Policies providing adequate notice of its privacy, data protection and data security practices regarding the Processing of information, including Personal Information, and (B) the Company Group has at all times posted such Privacy Policies in a clear and conspicuous location on the Company’s external websites and on internal Company websites (as relevant); (ii) true, correct and complete copies of all Privacy Policies (including all available prior and superseded versions thereof) have been provided to Parent; and (iii) no member of the Company Group has made any false or misleading statements in its Privacy Policy or marketing materials. No member of the Company Group has received any written complaint or inquiry, nor is any Proceeding pending or threatened in writing against the Company Group, alleging any breach by the Company Group of any applicable Privacy and Data Security Obligations.
(c) The Company Group has at all times implemented and maintained in place appropriate (i) technical and organizational measures; (ii) administrative security programs, policies, procedures; and (iii) such other measures, in each case, that protect Company IT Systems and Personal Information in the possession or under the control of the Company Group against reasonably anticipated threats and hazards to their security and the unauthorized use or disclosure thereof, and include comprehensive plans, policies, procedures and administrative, technical and physical safeguards to protect the Company IT Systems and Personal Information and other material data in the possession or under the control of the Company Group from destruction, loss, alteration, damage, unauthorized access or disclosure or illegal or unauthorized Processing (“Security Policies”). The Company Group has at all times been in compliance with all applicable Security Policies.
(d) Except as set forth in Section 2.13(d) of the Disclosure Schedule, during the last three (3) years, there has not been (i) any material breach, unauthorized access or other actual or suspected non-compliance related to Privacy and Data Security Obligations, (ii) any information security or privacy breach event that has resulted in or would require notification to any Governmental Authority or other Person by or on behalf of the Company Group under any Privacy and Data Security Obligations, or (iii) any use, access or disclosure by any Person of any Company IT Systems or any Personal Information in the possession or under the control of the Company Group for any illegal or unauthorized purpose.
(e) No member of the Company Group has received notice of any claims, and there is no Proceeding pending or, to the Knowledge of the Company, being threatened or reasonably likely to be brought against the Company Group alleging either a material violation of any Person’s rights under, or non-compliance, breach or compromise of, any Privacy and Data Security Obligations.
(f) The Company Group Companies has at all times established legal basis, made all required disclosures to, and obtained all consents from, users, customers, employees, contractors, governmental bodies and other applicable third parties required by all applicable Privacy and Data Security Obligations and as necessary for their respective Processing of Personal Information in connection with the conduct of their business as it has been conducted and currently planned to be conducted, and has filed any and all required registrations with the applicable data protection authority.
(g) Except as set forth in Section 2.13(g) of the Disclosure Schedule, the Company and all other members of the Company Group have implemented reasonable physicalentered into written agreements, technical and administrative safeguards to protect the privacywhere required, operation, confidentiality, integrity and security of with all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Personthird parties, including each subcontractors, third-party vendors, suppliers and customers, that satisfy the requirements of the Privacy and Data Security Obligations, including by correctly identifying the roles and responsibilities of the parties to such agreements and incorporating any contractual provisions mandated by applicable Privacy Laws.
(h) Without limiting the foregoing, the Company Group Companies’ employees has taken steps to limit access to Personal Information to: (i) their respective personnel and contractorsto subcontractors and third-party vendors providing services to or on behalf of the Company Group (as applicable), in each case to those who have a need to know such Personal Information in the execution of their duties to the Company Group (as applicable) and (ii) such other Persons permitted to access such Personal Information in accordance with the Privacy Policies, and contractual obligations to which the Company Group is bound. In respect of any international transfers of Personal Information subject to the GDPR or the UK GDPR, the Company Group has valid data transfer safeguards in place that comply with the GDPR or the UK GDPR (as relevant).
Appears in 1 contract
Sources: Merger Agreement (Global Business Travel Group, Inc.)
Data Privacy and Security. Except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole:
(a) Each Group Company does not knowingly collect or process has implemented (i) written policies relating to the Processing of Personal Data contrary as and to law, to each Group Company’s knowledge. The Company has the extent required by applicable Law and (ii) reasonable data security safeguards in place that are sufficient designed to protect the security and integrity of its Company IT Systems and any Personal Data and confidential information in the Company’s possession or control from other Business Data, including implementing reasonable procedures designed to prevent unauthorized access by third Persons and to ensure that the operation introduction of Disabling Devices (collectively, the businesses of each “Privacy and Data Security Policies”). Each Group Company (including with respect to employee matters) are in compliance with all Privacy currently and Security Requirements since the Reference Date has complied in all material respectsrespects with (A) all applicable Privacy Laws and (B) any applicable Privacy and Data Security Policies (collectively, the “Privacy and Data Security Requirements”). No Group Company has inserted and, to the knowledge of the Company, no other Person has inserted or alleged to have inserted any Disabling Device in any of the Company IT Systems or Company Product.
(b) There are no The Company has not received notice of any pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (ii) the Office of the Privacy Commissioner of Canada, or (iii) any other Governmental Entity or (ivEntity) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Requirements.
(c) Since the Lookback Reference Date, (i) there has been no material unauthorized access, use, acquisition access to or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference Incidents with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, respect to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System Systems, or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Data Privacy and Security. (a) Each Except as would not have a Company Material Adverse Effect, each Private Group Company does not knowingly collect or process has implemented adequate written policies relating to the Processing of Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each Group Company extent required by applicable Law (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There are Except as would not have a Company Material Adverse Effect, there is no Proceeding pending Proceedingsor, nor has there been any Proceedings to the Company’s knowledge, threatened in writing, against any Private Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iiiii) any other Governmental Entity Entity, foreign or domestic or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Private Group Company is or was in violation of any applicable Privacy Lawsand Security Requirements, nor, to the Company’s knowledge, is there any basis for the foregoing.
(c) Since January 1, 2019, to the Lookback DateCompany’s knowledge, (i) there has been no material unauthorized accessaccess to, or use, acquisition disclosure, or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Private Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Private Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into any Company IT Systems, and (iii) none of the Private Group Companies has notified or Security Breaches been required to notify any Person of any Group Company systems networks(A) loss, communication equipment theft or damage of, or (B) other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized or unlawful access to, use or modification use, disclosure or other Processing of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data, except, in each case of clauses (i), (ii) and (iii), as would not have a Company Material Adverse Effect.
(d) Each Except as would not have a Company Material Adverse Effect, (i) each Private Group Company owns or has a license licenses to use the Company IT Systems as necessary to operate the business of each Private Group Company as currently conducted. The Group Companies , (ii) to the Company’s knowledge, all Company IT Systems are free from any defect, bug, virus or programming, design or documentation error and (iii) since January 1, 2019, there have not been any failures, breakdowns or continued substandard performance of any Company IT Systems that have caused a sufficient number failure or disruption of license seats for all Software included in the Company IT SystemsSystems other than routine failures or disruptions that have been remediated in the ordinary course of business.
(e) The Group Companies are To the knowledge of the Company, the consummation of this Agreement and have been in compliance in all material respects with all applicable any transfers of Personal Data necessary to give effect to the Agreement will not violate any Privacy and Security Requirements since the Lookback DateRequirement, except as would not have a Company Material Adverse Effect.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Business Combination Agreement (Montes Archimedes Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to lawThere is (and since January 1, 2019 there has been) no Proceeding pending or, to each Group the Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession , threatened against or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against involving any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iiiii) any other Governmental Entity Entity, foreign or domestic or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Group Company is or was in violation of any applicable Privacy LawsData Security Requirements. Except as otherwise set on Section 3.20(a) of the Company Disclosure Schedules, the Group Companies and the conduct of their business are in material compliance with all Data Security Requirements.
(cb) Since the Lookback DateJanuary 1, 2019, (i) to the Company’s knowledge, there has been no material unauthorized accessaccess to, or unauthorized use, acquisition disclosure, or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company orand the Group Companies have not been notified by any of its contractors with regard to any unauthorized access to, to the Company’s knowledgeor unauthorized use, any third party service provider disclosure, or Processing of Personal Data obtained from or on behalf of any a Group Company, and (ii) to the Company’s knowledge, there have been no Security Incidents or other unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date Systems, and (iii) none of the Group Companies is aware has notified or been required to notify any Person of any written or(A) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach (B) other unauthorized or incident. None of the Group Companies has received any written complaintsunlawful access to, claimsor use, demands, inquiries disclosure or other noticesProcessing of, including Personal Data, that would require notification to a notice of investigation, from any Person (including any or Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal pursuant to Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(dc) The Company IT Systems are sufficient in all material respects for the operation of the business as currently conducted by the Group Company. Each Group Company owns or has a license or other right to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in To the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physicalCompany’s knowledge, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems are (i) free from Malicious Code, and Personal Data (ii) in their possession or control from unauthorized access by any Person, including each sufficiently good working condition to effectively perform all information technology operations necessary for the operation of the Group Companies’ employees Business as currently conducted (except for ordinary wear and contractorstear). Since January 1, 2019, there have not been any material failures, breakdowns or continued substandard performance of any Company IT Systems that have caused a material failure or material disruption of the Company IT Systems other than routine failures or disruptions that have been remediated in the ordinary course of business.
Appears in 1 contract
Sources: Business Combination Agreement (ArcLight Clean Transition Corp. II)
Data Privacy and Security. (a) Each member of the Company Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information involved in the Company’s possession collection or control from unauthorized access by third Persons Processing of Personal Information has posted written privacy notices relating to the Processing of Personal Information (“Privacy and to ensure that Data Security Policies”) and is and has since the operation of the businesses of each Group Company Lookback Date (including with respect to employee mattersor since such Privacy and Data Security Policy was posted, whichever is later) are been in compliance with all such Privacy and Data Security Requirements Policies in all material respects.
(b) There are no pending ProceedingsActions, nor has there been any Proceedings Actions against any member of the Company Group Company initiated by (i) any Person; , (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iii) any other Governmental Entity Authority, or (iv) any regulatory entity or self-regulatory entity, in each case, alleging that any Processing of Personal Data Information by or on behalf of a member of the Company Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) to the Knowledge of the Company, there has been no material unauthorized access, use, acquisition or disclosure of Personal DataInformation, or confidential business information in the possession or control of any Group member of the Company orGroup, and, to the Knowledge of the Company’s knowledge, any third party service provider on behalf of any Group Company, the Company and (ii) to the Company’s knowledge, there have been no material unauthorized intrusions into or Security Breaches of any Group member of the Company Group’s systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ Company Group’s business. The Group Companies have not experienced any material successful There is no unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding code in any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security RequirementsCompany Products. Since the Lookback Date, none no member of the Company Group Companies have has provided or have has been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System Assets or Personal DataInformation.
(d) Each The Company Group Company owns or is and has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in material compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(fe) The Company Group Companies have has implemented reasonable and maintains adequate physical, technical and administrative safeguards designed to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems Assets and Personal Data Information in their its possession or control from unauthorized access by any Person, including each member of the Group Companies’ Company Group’s employees and contractors, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Company Group, taken as a whole. The Company Group has implemented reasonable procedures, satisfying the requirements of applicable Privacy and Security Requirements, to detect data security incidents and to protect Personal Information against loss and against unauthorized access, use, modification, disclosure, or other misuse.
(f) The members of the Company Group have taken commercially reasonable measures designed to ensure all material third party service providers, outsourcers, processors, or other third parties Processing Personal Information, in each case on behalf of the Company Group, (i) use commercially reasonable measures designed to comply with applicable Privacy and Security Requirements, and (ii) use reasonable security measures with respect to Personal Information.
(g) Each member of the Company Group: (i) conducts periodic vulnerability testing and risk assessments, and has procedures for identifying security incidents related to, their respective systems and products (collectively, “Information Security Reviews”); (ii) has procedures reasonably designed to correct any material exceptions or vulnerabilities identified in such Information Security Reviews; (iii) has made available true and accurate copies of all material third-party Information Security Reviews conducted in the past two (2) years; and (iv) has procedures surrounding the timely installation of software security patches and other fixes to identified technical information security vulnerabilities. Each member of the Company Group provides its employees with regular training on privacy and data security matters.
Appears in 1 contract
Sources: Share Purchase Agreement (PTC Inc.)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect and its Subsidiary have (i) implemented and at all times maintained reasonable and appropriate security procedures and practices, including backups and disaster recovery arrangements and hardware and computer software support and maintenance arrangements designed to minimize the risk of a material error, breakdown, or process failure of the IT Systems or security breach or other Personal Data contrary breach occurring, and if such an event were to lawoccur, designed to each Group Company’s knowledge. The Company has safeguards in place that are sufficient minimize any resulting material disruption to protect Personal Data their business, and confidential information in the Company’s possession or control from unauthorized access by third Persons and (ii) taken commercially reasonable steps to ensure that the operation any third party with access to any Personal Data collected by or on behalf of the businesses Company or its Subsidiary are contractually required to maintain appropriate safeguards to protect such Personal Data. To the Knowledge of each Group the Company, no third party has provided any Personal Data to the Company or its Subsidiary in violation of any applicable Law, legal requirement or binding guideline or standard relating to the Processing of any Personal Data (including with respect to employee matters) are in compliance with all the “Privacy and Security Requirements in all material respectsLaws”).
(b) There are no pending ProceedingsThe Company and its Subsidiary, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) and, to the United States Federal Trade CommissionKnowledge of the Company, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by Persons acting for or on behalf of the Company or its Subsidiary, have at all times materially complied with (i) all applicable Privacy Laws and (ii) all of the Company’s and its Subsidiary’s policies, notices and contractual obligations relating to the Processing of any Personal Data, ((i) and (ii), together, the “Privacy Requirements”). No Proceeding is pending, and neither the Company nor its Subsidiary has received any notice in writing of any claims, charges, investigations or regulatory inquiries, related to or alleging a Group Company is in material violation of any applicable Privacy LawsRequirements and, to the Knowledge of the Company, there are no facts or circumstances that could reasonably form the basis of any such claim, charge, investigation or regulatory inquiry.
(c) Since the Lookback Date, (i) there There has been no (A) material unauthorized accessloss, use, acquisition theft or disclosure of Personal Data, data or confidential business information in the possession or control of any Group Company or, security breach relating to the Company’s knowledgeor its Subsidiary’s data or (B) material unintended, any third party service provider on behalf of any Group Companyillegal, and (ii) to the Company’s knowledgeunauthorized or improper use or disclosure of, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use any Personal Data in the custody or modification of, or interference with Company IT Systems since the Lookback Date and none control of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices Company or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataits Subsidiary.
(d) Each Group Company owns or has a license to use Neither the Company IT Systems as necessary nor its Subsidiary is subject to operate any contractual requirement or other legal obligation that, following the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in Closing, would prohibit the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and or its Subsidiary from Processing any Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees manner in which the Company and contractorsits Subsidiary Processed such Personal Data prior to the Closing.
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that Entities complied and are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all Privacy Commitments. The Company Entities have implemented and maintained appropriate physical, technical and organizational security measures to prevent the unlawful Processing of Personal Information and unauthorized access, accidental loss or destruction of or damage to Personal Information in their respective control.
(b) No Company Entity has received any written notice from any Governmental Authority or any Person alleging that any Company Entity is or has been in breach of any Privacy Commitment or seeking to limit its use of Personal Information and, to the Knowledge of the Company, no such breach has occurred within the applicable statute of limitations for a claim arising out of such a breach. No Company Entity has received a written request, complaint or objection to its collection or use of Personal Information from any Governmental Authority or any Person.
(c) The Company Entities have at all times made all disclosures to and obtained consents from third Persons (or otherwise have an appropriate legal basis) required by applicable Privacy Laws prior to the Processing of any Personal Information from such Persons and none of such disclosures made or contained in any Privacy Policy of a Company Entity or in any such materials has been inaccurate, misleading, or deceptive or in violation of any applicable Privacy Laws, including by omission. No action is pending and, to the Knowledge of the Company, no Person has threatened to commence any action concerning any claim that any Company Entity has violated any Privacy Commitment in connection with, or relating to, any Personal Information or the Processing of Personal information by any Company Entity.
(d) The execution, delivery and performance of this Agreement and the Transactions comply, and will comply, in all material respects, with all Privacy Commitments. Following the Closing Date, the Company Entities will continue to be permitted to collect, store, use and disclose Personal Information held by the Company Entities on terms substantially similar to those in effect as of the date of this Agreement and to the same extent the Company Entities would have been able to had the Transactions not occurred.
(e) No Company Entity and, to the Knowledge of the Company, no Personal Information Processor, has experienced any material unauthorized access to, deletion or other misuse of, any Personal Information in its possession or control (a “Security Requirements since the Lookback DateIncident”) or made or been required to make any disclosure, notification or take any other action under any applicable Privacy Laws in connection with any Security Incident.
(f) The Group Companies Company Entities have implemented reasonable established and maintain appropriate technical, physical, technical administrative and administrative safeguards to protect the privacyorganizational policies, operation, confidentiality, integrity measures and security of all systems and technologies consistent with industry standards and in compliance with data security requirements under applicable Privacy Laws that ensure that Company IT Systems and Personal Data in their possession is protected against unauthorized access, use, modification, disclosure, misuse, or control from unauthorized access accidental or unlawful Processing. The Company Entities have not received any written complaint, proceeding, investigation (formal or informal) or claim against, any Company Entity, by any Personprivate party, including each data protection authority, the Federal Trade Commission, or any other Governmental Authority, foreign or domestic, with respect to the collection, use, retention, disclosure, transfer, storage, security, disposal, or other Processing of the Group Companies’ employees Company Data. There has been no unauthorized Processing of any Company Data and contractorsno event or circumstance has occurred or arisen in which Privacy Laws would require any Company Entity to notify a Governmental Authority of a data security breach, security incident or violation of any data security policy.
Appears in 1 contract
Data Privacy and Security. (a) Each Except as set forth on Section 3.20(a) of the Company Disclosure Schedules, each Group Company does not knowingly collect or process has implemented written internal and external policies relating to the Processing of Personal Data contrary as and to lawthe extent required by applicable Privacy Law (“Privacy and Data Security Policies”). Except as set forth on Section 3.20(a) of the Company Disclosure Schedules, to for the past three (3) years, each Group Company’s knowledge. The Company has safeguards at all times complied in place that are sufficient all material respects with all applicable Privacy Laws, the Privacy and Data Security Policies, and contractual obligations entered into by a Group Company relating to protect the Processing of Personal Data and confidential information in the Company’s possession any other applicable industry standards or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each requirements binding upon such Group Company (including with respect to employee matters) are in compliance with all collectively, the “Privacy and Security Requirements in all material respectsRequirements”).
(b) There are no The Company has not received notice of any pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity; or (iv) any regulatory state, federal, or self-regulatory entityinternational data protection authority, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy LawsRequirements.
(c) Since Except as set forth on Section 3.20(c) of the Lookback DateCompany Disclosure Schedules, for the past three (3) years, (i) there has been no material unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to and/or any of the Company’s knowledge, any third party service provider on behalf providers of any Group Company, Company and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches any Company IT Systems under the control of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for conducted in all Software included in the Company IT Systemsmaterial respects.
(e) The Each Group Companies are Company is, and have been at all times has been, in material compliance in all material respects with all legal requirements that are applicable Privacy to each Group Company’s business as presently conduct pertaining to sales, marketing, and Security Requirements since electronic communications, including, without limitation, the Lookback DateU.S. CAN-SPAM Act, the U.S. Telephone Consumer Protection Act (TCPA), and the Fair Credit Reporting Act (FCRA).
(f) The Each Group Companies have implemented Company has reasonable physical, technical and administrative safeguards procedures in place to ensure that the third parties with which such Group Company shares or transfers Personal Data are required to protect the privacy, operation, confidentiality, integrity and security confidentiality of all Company IT Systems and the shared or transferred Personal Data in their possession compliance with all applicable Privacy Requirements. Each Group Company has contractual arrangements with such third parties that comply with all applicable Privacy Requirements to the extent applicable to the third party’s services, use, or control from unauthorized access by any Person, including each processing of the Group Companies’ employees and contractorsPersonal Data.
Appears in 1 contract
Sources: Business Combination Agreement (Capstar Special Purpose Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient not received any written notice of any Proceeding pending nor, to protect Personal Data and confidential information in the Company’s possession Knowledge, is any Proceeding threatened, against or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against involving any Group Company or its Affiliates initiated by (i) any Person; (ii) the United States Federal Trade Commission, including any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each caseEntity, alleging that any Processing of Personal Data by or on behalf of a any Group Company or its Affiliates is or was in violation of any applicable Privacy LawsRequirements.
(b) The Group Companies take commercially reasonable measures designed to protect and maintain (i) the ownership and confidentiality of their material proprietary Company Intellectual Property and (ii) the security, confidentiality, continuous operation and integrity of their Company IT Systems (and all confidential data and Protected Data stored therein or transmitted thereby). The Group Companies have back-up and disaster recovery arrangements for the continued operation of their business in the event of a failure of its Company IT Systems that are, in the reasonable determination of the Company’s management team, commercially reasonable and in accordance with standard industry practice.
(c) Since There have been no unauthorized intrusions or breaches of security that has resulted in unauthorized use of, or access to, the Lookback DateCompany IT Systems or Protected Data that, pursuant to any applicable Law, would require the Company or a Subsidiary to notify customers or employees of such breach or intrusion.
(d) Except as would not, individually or in the aggregate, have, or be reasonably expected to result in, a Company Material Adverse Effect, (i) there has not been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information any Data Breach with respect to any Protected Data in the possession or control of any Group Company oror its Affiliates, or any of its contractors with regard to the Company’s knowledge, any third party service provider Protected Data obtained from or on behalf of any Group CompanyCompany or its Affiliates, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date or Protected Data, and (iii) none of the Group Companies is aware nor their Affiliates have been notified or been required to notify any Person of any written or(a) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authorityb) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT SystemsBreach.
(e) The Group Companies are Company’s and have been in compliance its Subsidiaries’ collection, use, disclosure, storage and transfer of Personal Data complies in all material respects with all Privacy Requirements. The execution, delivery and performance of the transactions contemplated by this Agreement do not materially violate the Company’s privacy policy as it currently exists or, to the extent any previous privacy policy of the Company remains applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession maintained by the Company or control from unauthorized access by any Personits Subsidiaries, including each of the Group Companies’ employees and contractorsas such previous privacy policy existed before.
Appears in 1 contract
Sources: Business Combination Agreement (Blockchain Coinvestors Acquisition Corp. I)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place and its Subsidiaries have developed, implemented and maintained a written data protection, data privacy and cybersecurity program (the “Data Protection Program”) that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable the Privacy Requirements. Since January 1, 2019, the Company and its Subsidiaries have not experienced any material Security Requirements since Incident. Since January 1, 2019, no Person has claimed any compensation or damages from the Lookback DateCompany or any of its Subsidiaries, or has brought, or threatened in writing to bring, any Action against the Company or any of its Subsidiaries, in each case, in relation to any actual or alleged Security Incident or otherwise for or arising as a result of any actual or alleged violation, breach or other non-compliance with or of any Privacy Requirement.
(fb) Except as set forth in Section 5.14(b) of the Company Disclosure Schedule, since January 1, 2019, the Company and its Subsidiaries have at all times complied in all material respects with all Privacy Requirements with respect to the Processing of Company PII. The Group Companies Company and its Subsidiaries are not, and since January 1, 2019, have implemented reasonable physicalnot been, technical subject to a Governmental Order of, or have received a written notice from, a Governmental Authority regarding, actual or alleged non-compliance with or violation of any Privacy Requirement.
(c) To the knowledge of the Company and administrative safeguards to protect except as set forth in Section 5.14(c) of the privacyCompany Disclosure Schedule, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including (i) each of the Group CompaniesCompany’s and its Subsidiaries’ employees third-party data suppliers, vendors, and contractorspartners that Process any Company PII or other Personally Identifiable Information on behalf of the Company or its Subsidiaries are in compliance in all material respects with the Privacy Requirements, and (ii) there have been no material unauthorized or illegal Processing, or other breach, violation or default (or event that, with or without the giving of notice or lapse of time, would constitute a breach, violation or default) by any such supplier, vendor or other partner of any Privacy Requirements. Since January 1, 2019, no Security Incident has occurred for which the Privacy Requirements would require the Company or its Subsidiaries to notify any Governmental Authority.
(d) The consummation of the Transactions will not breach any Privacy Requirement, except as would not reasonably be expected to be, individually or in the aggregate, material to the Company and its Subsidiaries, taken as a whole.
Appears in 1 contract
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process and its Subsidiaries comply, and during the past four (4) years have complied with (i) all Privacy and Information Security Requirements, (ii) their respective Privacy Notices, and (iii) their respective Contracts relating to Processing of Personal Data contrary (including any Personal Data transfer agreements) or cybersecurity (such as in relation to lawData Breaches). Neither the Company nor any of its Subsidiaries, nor, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession Knowledge, any other Person, has received any notice, allegation, complaint, or control from unauthorized access other communication, and, to the Company’s Knowledge, there is no pending investigation or Action by third Persons and to ensure that the operation any Governmental Authority or payment card association, regarding, in each case of the businesses above, any actual or possible violation of each Group Company (including any Privacy and Information Security Requirement by or with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsthe Company or its Subsidiaries.
(b) There are no pending ProceedingsNeither the Company nor its Subsidiaries, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company ornor, to the Company’s knowledge, any third party service provider of its or their respective Service Providers or others acting on behalf of any Group Companytheir behalf, and (ii) have had, or have, a Data Breach. Neither the Company nor its Subsidiaries have notified, or, to the Company’s knowledgeKnowledge, there have been no unauthorized intrusions into or Security Breaches required to notify, any Person of any Group Data Breach. The Company systems networksand its Subsidiaries employs and has employed commercially reasonable physical, communication equipment technical, and organizational safeguards that comply with all Privacy and Information Security Requirements to protect, or advise on the protection of, Personal Data or other technology necessary for Data within its custody or control against a Data Breach and requires the operations same of all Service Providers that Process Data on its behalf or advise on the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing protection of Personal Data or other Data.
(c) The Company and its Subsidiaries have provided all notices and opt-in or opt-out choices (and honored such choices), and obtained all consents, and satisfied all other requirements (including but not limited to notification to, or registration with, any Governmental Authority), in each case, in compliance with applicable Privacy and Information Security Requirements. Since Requirements and as necessary for the Lookback Date, none Company and its Subsidiaries’ respective Processing (including international and onward transfer) of data in connection with the conduct of the Group Companies have provided business as currently conducted and in connection with the consummation of the transactions contemplated hereunder. The Company and its Subsidiaries are not subject to any contractual requirements, Privacy Notices, or have been obligated to provide notice under other legal obligations that, following the Closing, would prohibit the Company or any Privacy and Security Requirements to regarding of its Subsidiaries from receiving or using Data or Personal Data in the manner in which the Company or any Security Breach or unauthorized access to of its Subsidiaries receive or use of any Company IT System such Data or Personal DataData prior to the Closing.
(d) Each Group of the Company and its Subsidiaries owns or has a license to use the Company IT Systems as necessary to operate the its business of each Group Company as currently conducted. The Group Companies Company and its Subsidiaries have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented taken reasonable physical, technical and administrative safeguards precautions designed to protect the privacy, operation, confidentiality, integrity integrity, and security of all Company the IT Systems and Personal Data in their possession all information stored or control contained therein or transmitted thereby from any loss, theft, or unauthorized access disclosure, use, access, interruption or modification by any Person. To Company’s knowledge, including each all IT Systems are (i) free from any Malicious Code, material defect, bug or programming, design or documentation error and (ii) in sufficiently good working condition to effectively perform all material information technology operations necessary for the operation of the Group Companies’ employees business of the Company and contractorsits Subsidiaries (except for ordinary wear and tear). There have not been any material failures, breakdowns, or continued substandard performance of any IT Systems that have caused a material failure or disruption of the IT Systems. The Company and its Subsidiaries have implemented, maintained and tested commercially reasonable disaster recovery procedures and facilities for the business of the Company and its Subsidiaries and all Data material to the respective businesses of the Company and its Subsidiaries has been regularly backed up in an encrypted manner and tested for restoration.
Appears in 1 contract
Data Privacy and Security. (a) Each Except as set forth on Section 3.22(a) of the Company Disclosure Schedules, each Group Company does not knowingly collect or process has implemented written internal and external policies relating to the Processing of Personal Data contrary as and to lawthe extent required by applicable Privacy Law (“Privacy and Data Security Policies”). Except as set forth on Section 3.22(a) of the Company Disclosure Schedules, for the past three (3) years, to the knowledge of the Company, each Group Company’s knowledge. The Company has safeguards in place that are sufficient at all times complied with all applicable Privacy Laws, the Privacy and Data Security Policies, and contractual obligations entered into by a Group Company relating to protect the Processing of Personal Data and confidential information in the Company’s possession any other applicable industry standards or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each requirements binding upon such Group Company (including with respect to employee matters) are in compliance with all collectively, the “Privacy and Security Requirements in all material respectsRequirements”).
(b) There are no The Company has not received notice of any pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity; or (iv) any regulatory state, federal, or self-regulatory entityinternational data protection authority, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy LawsRequirements.
(c) Since Except as set forth on Section 3.22(c) of the Lookback DateCompany Disclosure Schedules, for the past three (3) years, to the knowledge of the Company, (i) there has been no material unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to and/or any of the Company’s knowledge, any third party service provider on behalf providers of any Group Company, Company and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches any Company IT Systems under the control of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Each Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented has taken commercially reasonable physical, technical and administrative safeguards steps to protect (i) the privacy, operation, confidentiality, integrity and security of all the Company IT Systems and (ii) personal data in the Group Company’s possession or control, or otherwise processed by the Group Company, from unauthorized, accidental or unlawful use, disclosure and modification.
(e) To the knowledge of the Company, each Group Company is, and at all times has been, in compliance with all legal requirements that are applicable to each Group Company’s business as presently conduct pertaining to sales, marketing, and electronic communications, including, without limitation, the U.S. CAN-SPAM Act, the U.S. Telephone Consumer Protection Act (TCPA), and the Fair Credit Reporting Act (FCRA).
(f) Each Group Company has reasonable procedures in place to ensure that the third parties with which such Group Company shares or transfers Personal Data are required to protect the confidentiality of the shared or transferred Personal Data in their possession compliance with all applicable Privacy Requirements. Each Group Company has contractual arrangements with such third parties that comply with all applicable Privacy Requirements to the extent applicable to the third party’s services, use, or control from unauthorized access by any Person, including each processing of the Group Companies’ employees and contractorsPersonal Data.
Appears in 1 contract
Sources: Business Combination Agreement (Fortune Rise Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information Except as disclosed in the Company’s possession or control from unauthorized access by third Persons Commission Documents, the Company and to ensure that its Subsidiaries have at all times since the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements Business Combination Closing complied in all material respects.
respects with all applicable Privacy Laws, Privacy and Data Security Policies (bas defined below), and contractual commitments concerning the Payment Card Industry Data Security Standards (if any) There are (collectively, the “Privacy Requirements”). Except as disclosed in the Commission Documents, the Company and its Subsidiaries have implemented adequate written policies relating to the Processing of Personal Data as and to the extent required by applicable Law (“Privacy and Data Security Policies”). Except as disclosed in the Commission Documents, there is no pending Proceedingspending, nor has there been since the Business Combination Closing Date any Proceedings material Actions against the Company or any Group Company of its Subsidiaries initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Authority, foreign or domestic; or (iv) any regulatory or self-regulatory entity, in each case, entity alleging that any Processing of Personal Data by or on behalf of a Group the Company or any of its Subsidiaries is in violation of any applicable Privacy Laws.
(c) Since Requirements. Except as disclosed in the Lookback Commission Documents, since the Business Combination Closing Date, (i) there has been no material breach of security resulting in unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of the Company or any Group Company of its Subsidiaries (as applicable) or, to the Company’s knowledgeKnowledge, any third party service provider of their respective contractors with regard to any Personal Data obtained from or on behalf of the Company or any Group Companyof its Subsidiaries (as applicable), and (ii) to the Company’s knowledge, there have been no or any material unauthorized intrusions or breaches of security into or Security Breaches of any Group Company the systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use Company or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of its Subsidiaries (as applicable). Except as disclosed in the Group Companies’ Processing Commission Documents, the Company or one of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company its Subsidiaries owns or has a license to use the Company IT Systems as necessary to operate the business Business of each Group the Company and its Subsidiaries as currently conducted. The Group Companies To the Company’s Knowledge, except as disclosed in the Commission Documents, none of the IT Systems contain any worm, bomb, backdoor, clock, timer or other disabling device, code, design or routine that causes the software of any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized Person, except as would not, individually or in the aggregate, reasonably be expected to have a sufficient number of license seats for all Software included Material Adverse Effect. Except as disclosed in the Commission Documents, the Company IT Systems.
and its Subsidiaries have taken organizational, physical, administrative and technical measures required by Privacy Requirements consistent with standards prudent in the industry in which the Company and its Subsidiaries operate to protect (ei) The Group Companies are the integrity, security and operations of their information technology systems, and (ii) the confidential data owned by the Company or any of its Subsidiaries or provided by the Company’s or any Subsidiary’s customers, and Personal Data against data security incidents or other misuse, except where the failure to take such organizational, physical, administrative or technical measures would not, individually or in the aggregate, reasonably be expected to have been a Material Adverse Effect. Except as disclosed in compliance the Commission Documents, the Company and its Subsidiaries have implemented reasonable procedures, satisfying the requirements of applicable Privacy Laws in all material respects respects, to detect data security incidents and to protect Personal Data against loss and against unauthorized access, use, modification, disclosure or other misuse, except where the failure to implement such reasonable procedures would not, individually or in the aggregate, reasonably be expected to have a Material Adverse Effect. Except as disclosed in the Commission Documents, in connection with all each third-party service provider whose services are material to the Company or one of its Subsidiaries and involve the Processing of Personal Data on behalf of the Company or any of its Subsidiaries, the Company or one of its Subsidiaries has in accordance with Privacy Laws, since the Business Combination Closing Date, entered into valid data processing agreements with any such third party in accordance with applicable Privacy and Security Laws, except where the failure to enter into such valid data processing agreements with any such third party would not, individually or in the aggregate, reasonably be expected to have a Material Adverse Effect. Except as disclosed in the Commission Documents, there have not been any Actions related to any data security incidents or any violations of any Privacy Requirements since that have been asserted in writing against the Lookback Date.
(f) The Group Companies Company or any of its Subsidiaries, and, to the Company’s Knowledge, none of the Company or any of its Subsidiaries has received any written correspondence relating to, or written notice of any Actions with respect to, alleged violations by the Company or any of its Subsidiaries of, Privacy Requirements, in each case which Actions, if adjudicated adversely to the Company or any of its Subsidiaries, would, individually or in the aggregate, reasonably be expected to have implemented reasonable physicala Material Adverse Effect. Except as disclosed in the Commission Documents, technical and administrative safeguards to protect neither the privacy, operation, confidentiality, integrity and security Company nor any of all Company IT Systems and its Subsidiaries has transferred any Personal Data from the European Union or United Kingdom to a jurisdiction outside the European Economic Area or United Kingdom, other than in their possession or control from unauthorized access by any Person, including each accordance with Articles 45 and 46(2) of the Group Companies’ employees and contractorsGDPR, except as would not, individually or in the aggregate, reasonably be expected to have a Material Adverse Effect.
Appears in 1 contract
Sources: Common Stock Purchase Agreement (Alpha Healthcare Acquisition Corp Iii)
Data Privacy and Security. (a) Each Group Except as would not be reasonably be expected to be material to the Company, taken as a whole, the Company does not knowingly collect or process Personal Data contrary to lawand each Company Subsidiary are, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in since the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation date of the businesses of each Group Company (including with respect to employee matters) are incorporation has been, in compliance with all applicable Privacy and Security Requirements Requirements. The transactions contemplated by this Agreement will not result in all material respectsany liabilities in connection with any Privacy and Security Requirements, except where any such liability would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect.
(b) There are The Company and each Company Subsidiary has implemented policies relating to the Processing of Personal Data, privacy, data protection, cybersecurity, data security and the security of the Company’s and each Company Subsidiaries’ information technology systems, as and to the extent required by applicable Privacy Law (“Privacy and Data Security Policies”).
(c) Since the Company’s incorporation and each Company Subsidiary’s organization, there has been no Proceeding, there is no Proceeding pending Proceedings, nor has and there been is no Proceeding threatened in writing against the Company or any Proceedings against any Group Company Subsidiary initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , or (iiiii) any other Governmental Entity Entity, foreign or (ivdomestic) any regulatory or self-regulatory entitythat, in each case, alleging alleged that any Processing of Personal Data by or on behalf of a Group the Company or any Company Subsidiary is or was in violation of any applicable Privacy Lawsand Security Requirements or any Privacy and Data Security Policies.
(cd) Since To the Lookback DateCompany’s knowledge, since the Company’s date of incorporation, (i) there has have been no material unauthorized access, use, acquisition Security Incidents that have adversely affected the business or disclosure operations of Personal Data, the Company or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group CompanySubsidiary, and (ii) neither the Company nor any Company Subsidiary has notified, or has been required to the Company’s knowledgenotify, there have been no unauthorized intrusions into or Security Breaches any Person of any Group Company systems networks(A) loss, communication equipment theft or damage of, or (B) other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification ofuse, disclosure, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data Data, except with respect to (i) and (ii) as would not be reasonably be expected to be material to the Company or compliance with applicable Privacy any Subsidiary, taken as a whole. The Company and Security Requirements. Since each Company Subsidiary takes reasonable action to protect the Lookback Date, none security of the Group Companies have provided software, databases, systems, networks, Internet sites and confidential information under their control from any unauthorized use, interruption, access or have been obligated to provide notice under any modification and comply with all Privacy and Security Requirements with regard to regarding any Security Breach or unauthorized access to or use the transmission and storage of any such information. The Company IT System or Personal Dataand each Company Subsidiary maintains reasonable disaster recovery, data breach and security plans, procedures and facilities consistent in all material respects with industry standards and practices.
(de) Each Group The Company owns or has a license valid right to use the Company IT Systems as necessary to operate the business of the Company and each Group Company Subsidiary as currently conducted. The Group Companies have a sufficient number To the knowledge of license seats for all Software included in the Company, the Company IT Systems.Systems owned by the Company are:
(ei) The Group Companies are free from any material defect, bug, virus or programming, design or documentation error; and
(ii) in good working condition to perform all material information technology operations necessary for the operation of the Business (except for ordinary wear and have been in compliance tear) as currently conducted in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) respects. The Group Companies have implemented Company has taken commercially reasonable physical, technical and administrative safeguards steps designed to protect the privacy, operation, confidentiality, integrity and security of all the Company IT Systems and Personal Data in their possession all material information stored or control contained therein or transmitted thereby from any theft, corruption, loss or unauthorized access use, access, interruption or modification by any Person. To the Company’s knowledge, including each since the Company’s date of incorporation, there have not been any material failures or continued substandard performance of any Company IT Systems that have caused a material failure of the Group Companies’ employees and contractorsCompany IT Systems.
Appears in 1 contract
Sources: Business Combination Agreement (Atlantic Coastal Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are is presently in compliance with with, and has at all Privacy and Security Requirements times been in compliance with, in all material respects, all applicable Privacy and Security Requirements. Each Group Company has implemented policies relating to the Processing of Personal Data as and to the extent required by applicable Privacy and Security Requirements.
(b) There are is no pending Proceedingspending, nor and since April 1, 2020, there has there not been any Proceedings asserted or, to the Company’s knowledge, threatened against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity, foreign or domestic; or (iv) any regulatory or self-regulatory entity, in each case, entity alleging that any Processing of Personal Data by breach or on behalf of a Group Company is in violation of any applicable Privacy Lawsand Security Requirement.
(c) Since To the Lookback DateCompany’s knowledge, since April 1, 2020 (i) there has been no material unauthorized access, use, acquisition access or disclosure other Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into use, access, intrusions, interruptions, modifications, corruptions or Security Breaches breaches (including any ransomware attacks) of security into, or other cyber or security incidents with respect to, any Company IT System, (iii) no Group Company has notified or been required to notify any Person of any Group Company systems networks(A) loss, communication equipment theft or damage of, or (B) other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized or unlawful access to, use or modification Processing of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number taken commercially reasonable precautions, to protect the confidentiality, integrity and security of license seats for the material Company IT Systems (and all Software included information and transactions stored or contained therein or transmitted thereby). All Company IT Systems are (i) to the Company’s knowledge, free from any “Trojan horse”, “virus”, “ransomware”, or other malicious code, material defect, bug, or programming, design or documentation error and (ii) in sufficiently good working condition to operate and perform in all material respects in accordance with their documentation and functional specifications and otherwise in the manner necessary for the operation of the business (except for ordinary wear and tear). To the Company’s knowledge, since April 1, 2020, there have not been any material failures or breakdowns of any Company IT Systems.
(e) The consummation of the Transactions shall not breach or otherwise cause any violation of any Privacy and Security Requirements, or result in any Group Companies are and have been Company being prohibited from receiving or using any Personal Data in compliance the manner currently received or used by such Group Company in all material respects with all applicable Privacy and Security Requirements since the Lookback Daterespects.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Business Combination Agreement (Forbion European Acquisition Corp.)
Data Privacy and Security. (a) Each Since March 31, 2019, each Group Company does not knowingly collect has been in compliance with Privacy Laws, and in all material respects with (i) Contracts (or process Personal Data contrary portions thereof) between such Group Company and other Persons relating to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in (ii) applicable written policies, public statements and other public representations relating to the Company’s possession Processing of Personal Data, inclusive of all disclosures required by applicable Privacy Laws (“Privacy and Data Security Policies,” and together with Privacy Laws and such Contracts, “Privacy Commitments”). The execution, delivery and performance by the Company of this Agreement and the Ancillary Documents to which the Company is or control from unauthorized access by third Persons will be a party, and to ensure that the operation consummation of the businesses transactions contemplated hereby or thereby, are not reasonably expected to, directly or indirectly, result in a violation of each any Privacy Commitments that would be materially adverse to the Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsCompanies, taken as a whole.
(b) Since March 31, 2019, the Privacy and Data Security Policies have at all times been maintained and made available to individuals in accordance with reasonable industry practices and as required by Privacy Laws, are accurate and complete and are not misleading or deceptive (including by omission). The practices of each Group Company with respect to the Processing of Personal Data conform in all material respects to the Privacy and Data Security Policies that govern such Personal Data.
(c) There are is (and in the prior three years there has been) no material Proceeding pending Proceedingsor, nor has there been any Proceedings to the Company’s knowledge, threatened against or involving any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iiiii) any other Governmental Entity Entity, foreign or domestic or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Group Company is or was in violation of any applicable Privacy LawsCommitments. To the Company’s knowledge, there are no facts, circumstances or conditions that would reasonably be expected to form the basis for any Proceeding for any potential violation of any Privacy Commitments.
(cd) Since In the Lookback Dateprior three years, (i) there has been no material unauthorized accessaccess to, or unauthorized use, acquisition disclosure, or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group CompanyCompany (“Security Incident”), and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date Systems, and (iii) none of the Group Companies is aware has notified or been required to notify any Person of any written or(A) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach (B) other unauthorized or incident. None of the Group Companies has received any written complaintsunlawful access to, claimsor use, demands, inquiries disclosure or other noticesProcessing of, including Personal Data, except, in each case of clauses (i), (ii), and (iii), as would not have a notice of investigationCompany Material Adverse Effect. Each Group Company has implemented commercially reasonable administrative, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of physical and technical safeguards to protect the Group Companies’ Processing confidentiality, integrity and security of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding against any Security Breach or unauthorized access Incident, including taking all reasonable steps to or use of any Company IT System or safeguard and back up Personal Data.
(de) Each Group Company owns or has a license or other right to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all All Company IT Systems are (i) free from any defect, bug, virus or programming, design or documentation error and Personal Data (ii) in their possession or control from unauthorized access by any Person, including each sufficiently good working condition to effectively perform all information technology operations necessary for the operation of the Group Companies’ employees businesses (except for ordinary wear and contractorstear), except in each case of clauses (i) and (ii), as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. In the prior three years, there have not been any material failures, breakdowns or continued substandard performance of any Company IT Systems that have caused a material failure or disruption of the Company IT Systems other than routine failures or disruptions that have been remediated in the ordinary course of business.
Appears in 1 contract
Sources: Business Combination Agreement (Environmental Impact Acquisition Corp)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process and its Subsidiaries have at all times for the past three (3) years complied in all material respects with all applicable Privacy Laws, Privacy and Data Security Policies (as defined below) and contractual commitments relating to the Processing of Personal Data contrary to law(collectively, to each Group Company’s knowledgethe “Privacy Requirements”). The Company has safeguards in place that are sufficient implemented adequate written policies relating to protect the Processing of Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons Data, as and to ensure that the operation of the businesses of each Group Company extent required by applicable Laws (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There are For the past three (3) years, there has not been any and, to the Company’s knowledge there is no pending Proceedings, nor has there been Proceeding against the Company or any Proceedings against any Group Company of its Subsidiaries initiated by (i) any Person; , (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iii) any other Governmental Entity Entity, foreign or domestic, or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group the Company or any of its Subsidiaries is in violation of any applicable Privacy LawsRequirements.
(c) Since To the Lookback DateCompany’s knowledge, during the past three (i3) years, there has been no material breach of security resulting in unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of the Company or any Group Company of its Subsidiaries or, to the Company’s knowledge, any third party service provider of its contractors with regard to any Personal Data obtained from or on behalf of the Company or any Group Companyof its Subsidiaries, and (ii) to or any unauthorized intrusions or breaches of security into the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companiesits Subsidiaries’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Datasystems.
(d) Each Group The Company owns and its Subsidiaries own or has have a license to use the Company IT Systems as necessary to operate the business of each Group Business as currently conducted, and the Company IT Systems operate and perform in a manner that permits the Company and its Subsidiaries to conduct the Business as currently conducted. The Group Companies have a sufficient number To the Company’s knowledge, none of license seats for all Software included in the Company IT SystemsSystems contain any worm, bomb, backdoor, clock, timer or other disabling device, code, design or routine that causes the Software of any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized person.
(e) The Group Companies are Company has taken commercially reasonable organizational, physical, administrative and technical measures required by the Privacy Requirements, and consistent with industry standards, designed to protect the integrity, security and operations of the Company IT Systems. The Company and its Subsidiaries have been in compliance implemented commercially reasonable procedures, satisfying the requirements of applicable Privacy Laws in all material respects with all applicable Privacy respects, designed to detect data security incidents and Security Requirements since the Lookback Dateto protect Personal Data against loss and against unauthorized access, use, modification, disclosure or other misuse.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security consummation of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees transactions contemplated by this Agreement or any of the Ancillary Documents will not violate any applicable Privacy Requirements, except as would not reasonably be expected to be, individually or in the aggregate, material to the Company and contractorsits Subsidiaries, taken as a whole, or as would not reasonably be expected to have, individually or in the aggregate, a material adverse effect on the ability of the Company and Pubco to consummate the Mergers.
Appears in 1 contract
Sources: Business Combination Agreement (Allurion Technologies Holdings, Inc.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledgehas implemented adequate written policies and procedures consistent with its obligations under Privacy Laws and maintains and enforced such policies and procedures. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Each Group Company (including with respect to employee matters) are is in all material respects in compliance with all applicable requirements of the Privacy Laws. No Group Company has received any written notice, order, complaint or other correspondence from any Governmental Entity or other person alleging a breach of, or non-compliance with, the Privacy Laws and Security Requirements so far as the Company is aware no circumstances exist which are likely to result in all material respectsany such notice, order, complaint or other correspondence being sent, served, given or made.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a valid, subsisting and enforceable license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted, and such Company IT Systems shall be owned or available for use by each Group Company following the Closing on terms and conditions substantially identical to those under which each Group Company owned or used such Company IT Systems as at the date of this Agreement. The Group Companies have a sufficient number of license seats for all Software included Except as is not and would not reasonably be expected to be, individually or in the Company IT Systems.
(e) The aggregate, material to the operation of the business of the Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physicalCompanies, technical and administrative safeguards to protect the privacytaken as a whole, operation, confidentiality, integrity and security of all Company IT Systems are: (i) free from any defect, bug, virus or programming, design or documentation error, and Personal Data (ii) in their possession or control from good working condition in all respects to effectively perform all information technology operations necessary for the operation of the Business in accordance with the specifications applicable to them (except for ordinary wear and tear), including for the avoidance of doubt, those under applicable Law. Since January 1, 2020, there have not been any failures, breakdowns, bugs in, security breaches, unauthorized access by or use or continued substandard performance of any PersonCompany IT Systems or unauthorized acquisition, including each destruction, damage, disclosure, loss, corruption, alteration or use of any data which have materially disrupted the operations of the Company.
(c) Each Group Companies’ employees Company has: (i) security measures, procedures or policies in place that are consistent with current industry practice to: (i) protect the Company IT Systems and contractorsany data held on such Company IT Systems; and (ii) prevent unauthorized access or the introduction of viruses or similar destructive code; and (ii) carried out regular reviews of the Company IT Systems and has remedied any weaknesses detected by such reviews.
(d) All material agreements relating to the Company IT Systems are provided under written agreements to which a Group Company is a party, and in respect of each such agreement: (i) it is in full force and effect, no notice having been given to terminate it; (ii) neither entering into, nor compliance with nor completion of, this Agreement will, or is likely to entitle a party to terminate, vary or make a claim under it; and (iii) the obligations of the Company or to the Company’s knowledge any other party under it have been complied with and no disputes have arisen in respect of it.
Appears in 1 contract
Sources: Business Combination Agreement (Armada Acquisition Corp. I)
Data Privacy and Security. (a) Each applicable Group Company does not knowingly collect or process involved in the collection of Personal Data contrary subject to lawapplicable Law has implemented and, where applicable, posted written privacy notices relating to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect the Processing of Personal Data and confidential information in to the Company’s possession or control from unauthorized access extent required by third Persons and to ensure that the operation of the businesses of each Group Company applicable Law (including with respect to employee matters) are in compliance with all “Privacy and Data Security Requirements in all material respectsPolicies”).
(b) There To the Company’s knowledge, there are no pending Proceedings, nor has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Policies.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business, except, in the case of clauses (i) and (ii), as would not have a Company Material Adverse Effect. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident, except in each case as would not have a Company Material Adverse Effect. None Except as would not have a Company Material Adverse Effect, (A) none of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since , and (B) since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have in place disaster recovery and security plans and procedures, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(e) The Except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards designed to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(g) To the extent required by applicable Law, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies have taken commercially reasonable measures designed to ensure all third party service providers, outsourcers, processors, or other third parties Processing Personal Data, in each case on behalf of the Group Companies, (i) use commercially reasonable measures designed to comply with applicable Privacy and Security Requirements; and (ii) use reasonable security measures with respect to Personal Data.
Appears in 1 contract
Sources: Business Combination Agreement (Dragoneer Growth Opportunities Corp.)
Data Privacy and Security. DOCPROPERTY "CUS_DocIDChunk0"
(a) Each Group Except as disclosed in the Commission Documents, the Company does not knowingly collect or process and its Subsidiaries have implemented written internal and external policies relating to the Processing of Personal Data contrary as and to lawthe extent required by applicable Privacy Law (“Privacy and Data Security Policies”). Except as disclosed in the Commission Documents, for the past three (3) years, each of the Company and its Subsidiaries has at all times complied in all material respects with all applicable Privacy Laws, the Privacy and Data Security Policies, and contractual obligations entered into by the Company or any of its Subsidiaries relating to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect the Processing of Personal Data and confidential information in any other applicable industry standards or requirements binding upon the Company’s possession Company or control from unauthorized access by third Persons and to ensure that any of its Subsidiaries (collectively, the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all “Privacy and Security Requirements in all material respectsRequirements”).
(b) There are no Except as disclosed in the Commission Documents, the Company has not received notice of any pending Proceedings, nor has there been any material Proceedings against the Company or any Group Company of its Subsidiaries initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity Entity; or (iv) any regulatory state, federal, or self-regulatory entityinternational data protection authority, in each case, alleging that any Processing of Personal Data by or on behalf of a Group the Company or any of its Subsidiaries is in violation of any applicable Privacy LawsRequirements.
(c) Since Except as disclosed in the Lookback DateCommission Documents, for the past three (3) years, (i) there has been no material unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of the Company or any Group of its Subsidiaries and/or any of the service providers of the Company or, to the Company’s knowledge, or any third party service provider on behalf of any Group Company, its Subsidiaries and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since under the Lookback Date and none control of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices Company or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataits Subsidiaries.
(d) Each Group of the Company and its Subsidiaries owns or has a license to use the Company IT Systems as necessary to operate the business of each Group the Company and its Subsidiaries as currently conducted. The Group Companies have a sufficient number of license seats for conducted in all Software included in the Company IT Systemsmaterial respects.
(e) The Group Companies are Each of the Company and have been its Subsidiaries is, and at all times has been, in material compliance in all material respects with all legal requirements that are applicable Privacy to each of the Company’s and Security Requirements since its Subsidiaries’ business as presently conduct pertaining to sales, marketing, and electronic communications, including, without limitation, the Lookback DateU.S. CAN-SPAM Act, the U.S. Telephone Consumer Protection Act (TCPA), and the Fair Credit Reporting Act (FCRA).
(f) The Group Companies have implemented Each of the Company and its Subsidiaries has reasonable physical, technical procedures in place to ensure that the third parties with which the Company and administrative safeguards its Subsidiaries shares or transfers Personal Data are required to protect the privacy, operation, confidentiality, integrity and security confidentiality of all Company IT Systems and the shared or transferred Personal Data in their possession or control from unauthorized access by any Person, including each compliance with all applicable Privacy Requirements. Each of the Group Companies’ employees Company and contractorsits Subsidiaries has contractual arrangements with such third parties that comply with all applicable Privacy Requirements to the extent applicable to the third party’s services, use, or processing of Personal Data.
Appears in 1 contract
Sources: Common Stock Purchase Agreement (Gelesis Holdings, Inc.)
Data Privacy and Security. Except as has not had or would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect:
(a) Each Group Company does not knowingly collect or process has implemented written policies relating to the Processing of Personal Data contrary as and to law, to each the extent required by applicable Law (“Company Privacy and Data Security Policies”). Each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with at all Privacy and Security Requirements times complied in all material respectsrespects with all applicable Privacy Laws, the Company Privacy and Data Security Policies and contractual obligations entered into by a Group Company relating to the receipt, collection, compilation, use, storage, processing, sharing, safeguarding, security, disposal, destruction, disclosure or transfer of Personal Data (collectively, the “Company Privacy Requirements”).
(b) There are no As of the date hereof, the Company has not received notice of any pending Legal Proceedings, nor has there been any material Legal Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityAuthority, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Company Privacy LawsRequirements.
(c) Since the Lookback Dateincorporation of the Company, (i) there has been no material unauthorized access, use, acquisition or disclosure Processing of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to and/or any of the Company’s knowledge, any third party service provider on behalf providers of any Group Company, Company and (ii) to the Company’s knowledgeKnowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches any Company IT Systems under the control of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license binding Contract in place to use the Company IT Systems as necessary to operate the business of each Group Company Business as currently conducted. The Group Companies have a sufficient number of license seats for conducted in all Software included in the Company IT Systemsmaterial respects.
(e) The Each Group Companies Company has established data safeguards against the destruction, loss, damage, corruption, alteration, loss of integrity, commingling or unauthorized access, acquisition, use, disclosure or other Processing of Personal Data that are consistent with industry standards and have been in compliance in all material respects with all the requirements of applicable Privacy and Security Requirements since the Lookback Date.
(f) The Law. Each Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security Company maintains backups of all data used to conduct the business of such Group Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorsat a reasonable frequency.
Appears in 1 contract
Sources: Merger Agreement (Flexible Solutions International Inc)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process has implemented written policies relating to the Processing of Personal Data contrary as and to lawthe extent required by applicable Law (“Privacy and Data Security Policies”). No Group Company has violated any applicable Privacy Requirements in any material respect, to and each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company Business (including with respect to employee mattersthe Processing of Personal Data) are complies, and has completed, in compliance all material respects with all Privacy Requirements. The transactions contemplated by this Agreement and Security Requirements in all material respectsthe consummation thereof will not violate any applicable Privacy Requirement.
(b) There are no pending Proceedings, nor has there have not been any material Proceedings against any Group Company initiated by (i) any Person; , (ii) the United States Federal Trade Commission, any state attorney general or similar state official; official or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityEntity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy LawsRequirements or with respect to any Security Incident, and no Group Company has received written notice of any pending or threatened Proceedings, or provided (or been required to provide) notice to any Person, with respect to any of the foregoing or any Processing of Personal Data. Each Group Company has, with respect to all third party Company Data and all other material Company Data, all rights necessary to operate the business of such Group Company as currently conducted. All Company Data will continue to be available for Processing by and on behalf of the Group Companies following the Closing on terms and conditions identical to those under which the Company Data was available for Processing by and on behalf of the Group Companies immediately prior to the Closing, without payment of any additional amounts or consideration. No Group Company has received any written communication from any Person from whom it acquires, purchases, is provided, or engages in any other business relationship with respect to, Company Data to the effect that, and no Group Company has any reason to believe that, any such Person will stop or decrease the rate of, or materially alter the terms of, the business it conducts with (or the Company Data it provides for) the Group Companies. There are no suppliers of Company Data that are subjected to any Processing in connection with the Business or any Company IT System with respect to which practical alternative sources of supply are not generally available on comparable terms (including price) and conditions in the marketplace.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conductedconducted in all material respects. The Company IT Systems are, in all material respects, sufficient and in good working condition (subject to ordinary course maintenance and upgrades) for the operation of the Business as currently operated. The Group Companies have a sufficient number maintain commercially reasonable security, disaster recovery and business continuity plans, procedures and facilities, and act in compliance therewith. To the knowledge of license seats for all Software included in the Company, the Company IT Systems.
(e) Systems are free from Malicious Code. The Group Companies are Company at all times (x) when such encryption would be reasonably required to meet industry security standards encrypts Personal Data in transit and have at rest on all Company IT Systems, and (y) encrypts sensitive Personal Data (e.g., bank account information and social security numbers) in transit and at rest on all Company IT Systems. Since December 31, 2019, (i) no Group Company has been in compliance subject to or experienced a Security Incident, and (ii) none of the Company IT Systems has had any material failures, breakdowns, continued substandard performance, or other adverse events that has not been remedied or replaced in all material respects with all applicable Privacy and Security Requirements since the Lookback Daterespects.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Business Combination Agreement (Proptech Investment Corp. Ii)
Data Privacy and Security. (a) Each applicable Group Company does not knowingly collect or process involved in the collection of Personal Data contrary subject to lawapplicable Law has implemented and, where applicable, posted written privacy notices relating to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect the Processing of Personal Data to the extent required by applicable Law (“Privacy and confidential information Data Security Policies”), except as would not reasonably be expected to be, individually or in the Company’s possession or control from unauthorized access by third Persons and aggregate, material to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsCompanies, taken as a whole.
(b) There Except as set forth in Section 3.20(b) of the Company Disclosure Schedules, there have not been any material Proceedings, nor to the Company’s knowledge are no there any pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Policies.
(c) Since Except as set forth in Section 3.20(c)(i) of the Company Disclosure Schedules, since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure Security Breach of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business, except, in the case of clauses (i) and (ii), as would not have a Company Material Adverse Effect. The Except as set forth in Section 3.20(c)(ii) of the Company Disclosure Schedules, the Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident, except in each case as would not have a Company Material Adverse Effect. None Except as set forth in Section 3.20(c)(iii) of the Company Disclosure Schedules, (A) none of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since , and (B) since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the material Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have in place disaster recovery and security plans and procedures, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(e) The Except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole, the Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards designed to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole.
(g) The Group Companies have used commercially reasonable efforts to ensure that all third party service providers Processing Personal Data, in each case on behalf of the Group Companies, to (i) to maintain confidentiality of and use Personal Data only for the provision of services to the Group Companies, (ii) comply with applicable Privacy and Security Requirements; and (iii) use reasonable physical, technical and administrative safeguards to secure Personal Data from loss, theft, unauthorized access, use, modification, disclosure or other misuse.
(h) The Group Companies own or have a valid and sufficient basis, license or other right, permission, or consent to collect and use all data used in or necessary for the conduct of their business as currently conducted consistent with Privacy and Security Requirements, except as is not and would not reasonably be expected to be, individually or in the aggregate, material to the Group Companies, taken as a whole. Except as set forth in Section 3.20(h) of the Company Disclosure Schedules, to the Group Companies’ knowledge, (i) none of the Group Companies has been or is in material breach of any Contract, and (ii) the consummation of the transactions contemplated herein will not result in the loss or impairment of the Group Companies’ basis or rights to use any data and will not result in the breach of, or create on behalf of any party, the right to terminate or modify any Contract to which any of the Group Companies is a party and pursuant to which any of the Group Companies is authorized or licensed to use any third-party data.
(i) The Group Companies have, on each website and online service operated by the Group Companies, posted a privacy policy conforming in all material respects with all applicable Privacy Laws. Each such privacy policy accurately discloses how the Group Company Processes Personal Data.
Appears in 1 contract
Sources: Business Combination Agreement (Dragoneer Growth Opportunities Corp. II)
Data Privacy and Security. (a)
(a) Each The Group Company does not knowingly collect or process Personal Data contrary to lawCompanies have taken commercially reasonable steps including through implementing policies and procedures, to each Group Company’s knowledgecomply with the Privacy Obligations, including through adopting and externally publishing privacy notices and/or policies that accurately describe their privacy practices in all material respects (“Privacy Notices”). The Company has safeguards Group Companies are and, during the three years prior to the date of this Agreement have been, in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in material compliance with all applicable: (i) Privacy Obligations and Security Requirements in all material respects(ii) Privacy Notices.
(b) There Sellers and their Subsidiaries, with respect to the business of the Group Companies have implemented and maintain an information security program, documented in writing, comprising commercially reasonable safeguards designed to protect Personal Information and the IT Assets that are owned or controlled by the Group Companies, materially consistent with applicable Privacy Obligations. The Group Companies process payment card data in compliance in all material respects with the Payment Association Rules and Laws applicable to the security of payment card data, and no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) has received any Person; (ii) written notice from any payment brand or other payment association alleging non-compliance with the United States Federal Trade Commission, any state attorney general Payment Association Rules or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing Laws applicable to the security of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Lawspayment card data.
(c) Since Except as set forth in Schedule 3.14(c), as of the Lookback Datedate hereof, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, with respect to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations business of the Group Companies’ business. The Group Companies have not experienced , there is no Action pending against the Sellers or any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of and Sellers have not received any written or, to the knowledge of the CompanySellers, oral notices complaint, investigation, claim, demand or complaints other notice during the three years prior to the date of this Agreement from any Governmental Authority or any Person regarding such a any Security Breach Incident or incident. None of alleging that the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or are not in compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy Obligations, and Security Requirements to regarding the knowledge of Sellers, there is no reasonable basis for any Security Breach or unauthorized access to or use of any Company IT System or Personal Datasuch Action.
(d) Each Within the three years prior to the date of this Agreement, there have been no material Security Incidents experienced by any Group Company. No Group Company owns has notified, or has a license been required by applicable Law, Governmental Authority, or other Privacy Obligation to use the Company IT Systems as necessary to operate the business notify, individuals or Governmental Authorities of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systemsany Security Incident.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Equity Purchase Agreement (Topgolf Callaway Brands Corp.)
Data Privacy and Security. (a) Each The Company has not received any written notice of any pending or threatened Proceeding against or involving any Group Company does not knowingly collect or process Personal Data contrary to lawor, to each the Company’s Knowledge, any Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company Affiliates initiated by (i) any Person; (ii) the United States Federal Trade Commission, including any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each caseEntity, alleging that any Processing of Personal Data by or on behalf of a any Group Company or its Affiliates is or was in violation of any applicable Privacy LawsRequirements.
(b) The Group Companies take, in the reasonable determination of the Company’s management team, commercially reasonable measures designed to protect and maintain (i) the ownership and confidentiality of their material proprietary Company Intellectual Property and (ii) the security, confidentiality, continuous operation and integrity of their Company IT Systems (and all confidential data and Protected Data stored therein or transmitted thereby). The Group Companies have back-up and disaster recovery arrangements for the continued operation of their business in the event of a failure of its Company IT Systems that are, in the reasonable determination of the Company’s management team, commercially reasonable and in accordance with standard industry practice.
(c) Since Except as would not, individually or in the Lookback Dateaggregate, have, or be reasonably expected to result in, a Company Material Adverse Effect, (i) there has not been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information any Data Breach with respect to any Protected Data in the possession or control of any Group Company oror its Affiliates, or any of its contractors with regard to the Company’s knowledge, any third party service provider Protected Data obtained from or on behalf of any Group CompanyCompany or its Affiliates, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date or Protected Data, and (iii) none of the Group Companies is aware nor their Affiliates have been notified or been required to notify any Person of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Data Breach or incident. None other intrusion or breach of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of security into any Company IT System Systems or Personal Protected Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business The Company’s and its Subsidiaries’ collection, use, disclosure, storage and transfer of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance Personal Data complies in all material respects with all Privacy Requirements. The execution, delivery and performance of the transactions contemplated by this Agreement do not materially violate the Company’s privacy policy as it currently exists or, to the extent any previous privacy policy of the Company remains applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession maintained by the Company or control from unauthorized access by any Personits Subsidiaries, including each of the Group Companies’ employees and contractorsas such previous privacy policy existed before.
Appears in 1 contract
Sources: Business Combination Agreement (Calisa Acquisition Corp)
Data Privacy and Security. (ai) Each Group Company does not knowingly collect or process Personal Data contrary to lawThe Company, to each Group Company’s knowledge. The Company of its subsidiaries and each Licensed Entity complies, and during the past three years has safeguards complied, in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance all material respects, with all Privacy and Information Security Requirements in all material respects.
(b) There are no pending ProceedingsRequirements. None of the Company, any of its subsidiaries, nor any Licensed Entity has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) notified in writing of, or is the United States Federal Trade Commissionsubject of, any state attorney general complaint or similar state official; (iii) any other Governmental Entity proceeding or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any, regulatory investigation related to Processing of Personal Data by any third party service provider on behalf Governmental Authority or payment card association, regarding any actual or possible violations of any Group Privacy and Information Security Requirement by or with respect to the Company, and any of its subsidiaries or any Licensed Entity.
(ii) The Company, each of its subsidiaries and each Licensed Entity employs commercially reasonable organizational, administrative, physical and technical safeguards that comply in all material respects with all Privacy and Information Security Requirements to protect Company Data within its custody or control and requires the same of all vendors under contract with the Company that Process Company Data on its behalf. The Company, each of its subsidiaries and each Licensed Entity has provided all requisite notices and obtained all required consents, and satisfied all other requirements (including but not limited to notification to Governmental Authorities), necessary for the Processing (including international and onward transfer) of all Personal Data in connection with the conduct of the business as currently conducted and in connection with the consummation of the transactions contemplated hereunder.
(iii) To the knowledge of the Company, none of the Company, any of its subsidiaries nor any Licensed Entity has suffered a security breach with respect to any of the Company Data and to the Company’s knowledge, there have has been no unauthorized intrusions into or Security Breaches illegal use of or access to any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ businessData. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge None of the Company, oral notices any of its subsidiaries nor any Licensed Entity has notified, or complaints from been required to notify, any Person regarding person of any information security breach involving Personal Data. To the Company’s knowledge, the Company Systems have had no material errors or defects that have not been fully remedied and contain no code designed to disrupt, disable, harm, distort or otherwise impede in any manner the legitimate operation of such a Security Breach Company Systems (including what are sometimes referred to as “viruses”, “worms”, “time bombs” or incident“back doors”) that have not been removed or fully remedied. None of the Group Companies Company, any of its subsidiaries nor any Licensed Entity has received experienced any written complaintsmaterial disruption to, claimsor material interruption in, demandsthe conduct of its business that affected the business for more than one calendar week, inquiries and attributable to a defect, bug, breakdown, unauthorized access, introduction of a virus or other noticesmalicious programming, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of other failure or deficiency on the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use part of any Company IT System computer software or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Arrangement Agreement
Data Privacy and Security. (a) Each Group Section 3.21(a) of the Disclosure Schedule sets forth a complete list of all current (as of the date of this Agreement): (i) data privacy and security policies of the Company, whether applicable internally, published by the Company does not knowingly collect or process its Subsidiaries, including on a website, or otherwise made available by the Company or any of its Subsidiaries to any Person (“Company Privacy Policies”); and (ii) notifications and registrations made by the Company with relevant Governmental Entities in connection with Personal Data contrary to law, to each Group Company’s knowledge. The (“Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsRegistrations”).
(b) There are no pending ProceedingsExcept as set forth in Section 3.21(b) of the Disclosure Schedule, nor has there been since January 1, 2017, the Company’s data, privacy and security practices have conformed with in all material respects, and the execution, delivery and performance of this Agreement will not cause, constitute, or result in a breach or violation of, Privacy Laws, the Company Privacy Policies, the Company Privacy Registrations and any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Contract relating to Personal Data by to which the Company or on behalf of its Subsidiaries is a Group party or is otherwise bound (“Company is in violation of any applicable Data Agreements”) (collectively, “Company Privacy LawsCommitments”).
(c) Since Except as set forth in Section 3.21(c) of the Lookback DateDisclosure Schedule, (i) there the Company has been no material unauthorized accessnot received any subpoenas, use, acquisition or disclosure of Personal Datademands, or confidential business information in the possession other notices from any Governmental Entity investigating, inquiring into, or control otherwise relating to any actual or potential violation of any Group Privacy Laws, and to Seller’s Knowledge, the Company or, to the Company’s knowledge, is not under investigation by any third party service provider on behalf Governmental Entity for any violation of any Group Company, Privacy Law; and (ii) to the Company’s knowledge, there have no Action has been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written served on or, to Seller’s Knowledge, initiated or threatened in writing against the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use Company alleging violation of any Company IT System or Personal DataPrivacy Commitments.
(d) Each Group Company owns or has a license to use the Company IT Systems Except as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included set forth on Section 3.21(d) in the Company IT Systems.
(e) The Group Companies are and have been Disclosure Schedule, no violation of any data security policy, breach, or unauthorized access in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards relation to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession the Company’s possession, custody or control from unauthorized access by any Person, including each or material security incident has occurred. No circumstance has arisen in which: (i) Applicable Laws would require the Company to notify a Governmental Entity of a data security breach or security incident or (ii) applicable guidance or codes or practice promulgated under Applicable Law would recommend the Group Companies’ employees and contractorsCompany to notify a Governmental Entity of a data security breach or security incident.
Appears in 1 contract
Sources: Equity Purchase Agreement (Centerpoint Energy Resources Corp)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or has administrative, technical and physical safeguards (including monitoring compliance with such safeguards) to protect the confidentiality, privacy and security of Personal Information and the systems, technology and networks that process Personal Data contrary to law, to each Group Company’s knowledgeInformation (the "Company Information Security"). The Company has safeguards in place that are sufficient produced to protect Personal Data the Purchaser true, correct and confidential information in complete copies of all written policies and procedures related to the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsInformation Security.
(b) There are no pending ProceedingsTo the Knowledge of the Company, neither the Company nor any of the Company Subsidiaries has there been any Proceedings against any Group Company initiated by experienced: (i) any Personunauthorized processing of Personal Information in the possession, custody or control of any of the Company or the Company Subsidiaries; or (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing unauthorized processing by a third party of Personal Data by Information processed for or on behalf of the Company or any of the Company Subsidiaries. The Company and each of the Company Subsidiaries has not knowingly acted in a Group Company manner, and is in violation not aware of any applicable Privacy Lawsincident, that would trigger an obligation to notify any person or Governmental Authority under any Laws or Contract.
(c) Since The Company and each of the Lookback Date, Company Subsidiaries is in material compliance with (i) there has been no material unauthorized access, use, acquisition or disclosure of all Laws related to Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, Information; and (ii) all policies, procedures, processes, statements or notices related to Personal Information to the Company’s knowledgeextent such policies, there have been no unauthorized intrusions into procedures, processes, statements or Security Breaches of any Group Company systems networks, communication equipment notices are legally binding or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, give rise to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person legally-enforceable duties (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable "Privacy and Security Legal Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data").
(d) Each Group The Company owns or has a license to use and each of the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been Subsidiaries either transmits Personal Information across jurisdictional borders in compliance in all material respects with all applicable Privacy Legal Requirements or processes Personal Information exclusively in the same jurisdiction as each data subject to which it relates resides.
(e) The Company and Security Requirements since each of the Lookback DateCompany Subsidiaries has entered into written agreements with each third party service provider, vendor and business partner that processes Personal Information, such as payment card processors, advertising and marketing agencies, cloud storage vendors and outsourced technology or human resource functions (collectively, "Data Related Vendors"), containing commercially reasonable provisions for data privacy and security. The Company and each of the Company Subsidiaries has taken reasonable steps to select and retain only those Data Related Vendors that it considers to be capable of maintaining the confidentiality, privacy and security of the Personal Information that they process on behalf of the Company and the Company Subsidiaries.
(f) The Group Companies have implemented reasonable physicalNo person has commenced or, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each Knowledge of the Group Companies’ employees Company, threatened within the past five years any Legal Action or other written complaint, audit, proceeding, claim or investigation arising from or relating to processing by, for or on behalf of the Company or any of the Company Subsidiaries.
(g) The execution, delivery and contractorsperformance of this Agreement and the consummation of the transactions contemplated herein shall not cause, constitute or result in a breach or violation of any Privacy Legal Requirement, any policy, procedure, process, statement or notice of the Company or any of the Company Subsidiaries as it currently exists or as it existed at any time during which any Personal Information was processed by or on behalf of the Company or any of the Company Subsidiaries.
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary The Business and Sellers (to lawthe extent Related to the Business) comply with, and have for the three (3) years prior to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements date hereof complied with, in all material respects, all Data Protection Laws, internal or publicly posted policies, procedures, agreements, and notices, and in connection with the collection, access, processing, use, storage, disclosure, transmission, or transfer (including cross-border transfer) of Personal Information, the requirements of any Material Contract and/or applicable industry standards, including the Payment Card Industry Data Security Standard (collectively the “Data Protection Requirements”). None of the Sellers has used, disclosed, transferred, or otherwise processed any Personal Information that is Related to the Business in any manner that violates any Data Protection Requirement.
(b) There are no pending ProceedingsIn each case to the extent Related to the Business, nor none of the Sellers has there been received any Proceedings against subpoenas, demands, or other notices from any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity investigating, inquiring into, or (iv) otherwise relating to any regulatory actual or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in potential violation of any applicable Privacy LawsData Protection Law and, to the Knowledge of the Sellers, none of the Sellers is under investigation by any Governmental Entity for any actual or potential violation of any Data Protection Law.
(c) Since No notice, complaint, claim, enforcement action, or litigation of any kind that is Related to the Lookback DateBusiness has been served on, or initiated against the Sellers or the Business under any applicable Data Protection Requirement.
(d) The Sellers have established and maintain physical, technical, and administrative security measures and policies, compliant with applicable Data Protection Requirements, that (i) there protect the operation, confidentiality, availability, integrity, and security of the Sellers’ and the Business’s software, systems, and websites that are involved in the collection and processing of Personal Information and/or business data for the Business, and (ii) identify internal and organizational risks to the confidentiality, integrity, security, and availability of Personal Information of the Business and/or business data and data systems of the Business.
(e) To the Knowledge of Sellers, none of the Business or the Sellers has been no material experienced any security breaches or incidents, unauthorized access, use, acquisition or disclosure of Personal Datamodification, or confidential business information in the possession or control of any Group Company ordisclosure, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations adverse events or incidents related to Personal Information of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access toBusiness and/or business data and data systems of the Business that would require notification of individuals, use or modification ofother affected parties, law enforcement, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback DateEntity.
(f) Each Seller with respect to the Business has made all required registrations and notifications in accordance with all applicable Data Protection Requirements, and all such registrations and notifications are current, complete, and accurate in all respects.
(g) The Group Companies have implemented reasonable physicalexecution, technical delivery, and administrative safeguards to protect performance of this Agreement shall not cause, constitute, or result in a breach or violation of any Data Protection Requirement or other standard terms of service entered into by the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each users of the Group Companies’ employees and contractorsBusiness’s service(s).
Appears in 1 contract
Sources: Asset Purchase Agreement (Sequential Brands Group, Inc.)
Data Privacy and Security. (ai) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company and each of its subsidiaries complies, and during the past three years has safeguards complied, in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance all material respects, with all Privacy and Information Security Requirements Requirements. Neither the Company nor any of its subsidiaries has been notified in all material respects.
(b) There are no pending Proceedingswriting of, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) or is the United States Federal Trade Commissionsubject of, any state attorney general complaint or similar state official; (iii) any other Governmental Entity proceeding or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any, regulatory investigation related to Processing of Personal Data by any third party service provider on behalf Governmental Authority or payment card association, regarding any actual or possible violations of any Group Company, Privacy and Information Security Requirement by or with respect to the Company or any of its subsidiaries.
(ii) The Company and each of its subsidiaries employs commercially reasonable organizational, administrative, physical and technical safeguards that comply in all material respects with all Privacy and Information Security Requirements to protect Company Data within its custody or control and requires the same of all vendors under contract with the Company that Process Company Data on its behalf. The Company and each of its subsidiaries has provided all requisite notices and obtained all required consents, and satisfied all other requirements (including but not limited to notification to Governmental Authorities), necessary for the Processing (including international and onward transfer) of all Personal Data in connection with the conduct of the business as currently conducted and in connection with the consummation of the transactions contemplated hereunder.
(iii) To the knowledge of the Company, neither the Company nor any of its subsidiaries has suffered a material security breach with respect to any of the Company Data and to the Company’s knowledge, there have has been no unauthorized intrusions into or Security Breaches illegal use of or access to any Company Data which would result in a Material Adverse Effect. Except as set forth in Section 3.1(t)(iii) of the Company Disclosure Letter, neither the Company nor any of its subsidiaries has notified, or been required to notify, any person of any Group information security breach involving Personal Data. To the Company’s knowledge, the Company systems networks, communication equipment Systems have had no material errors or other technology necessary for the operations of the Group Companies’ business. The Group Companies defects that have not been fully remedied and contain no code designed to disrupt, disable, harm, distort or otherwise impede in any material manner the legitimate operation of such Company Systems (including what are sometimes referred to as “viruses”, “worms”, “time bombs” or “back doors”) that have not been removed or fully remedied. Neither the Company nor any of its subsidiaries has experienced any material successful unauthorized access disruption to, use or modification ofmaterial interruption in, the conduct of its business that affected the business for more than one calendar week, and attributable to a defect, bug, breakdown, unauthorized access, introduction of a virus or other malicious programming, or interference with Company IT Systems since other failure or deficiency on the Lookback Date and none of the Group Companies is aware part of any written or, to the knowledge of the Company, oral notices computer software or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process Personal Data contrary to lawand its Subsidiaries and, to each Group the Knowledge of the Company, its Data Partners, comply and, within the last five years, have complied in all material respects with all Privacy Laws, Company Privacy Policies and Contracts relating to the processing, privacy and security of Personal Information (collectively, the “Company Privacy Commitments”), including compliance with respect to (i) Personal Information of Company’s knowledgewebsite visitors, customers or representatives of Company customers, the Company’s or its Subsidiaries’ own employees, or any other individual whose Personal Information is processed by the Company or its Subsidiaries; and (ii) the sending of solicited or unsolicited electronic or telephonic communications, including via email, text message or phone call. The Company has safeguards in place that are sufficient to protect and its Subsidiaries have implemented and maintained processes for identifying and redacting any Personal Data and confidential information Information contained in the Company’s possession or control from unauthorized access Spaces created by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsPlatform.
(b) There are no pending ProceedingsNeither the execution, delivery and performance of this Agreement by the Company nor has there been any Proceedings against any Group the consummation by the Company initiated by of the transactions contemplated hereby will (i) trigger or require any notices to or consents from any Person; (ii) the United States Federal Trade Commission, violate any state attorney general Company Privacy Commitments; or similar state official; (iii) give rise to any right of termination or other Governmental Entity right to impair or limit the Company’s or its Subsidiaries’ right to own and process any Personal Information used in or necessary for the operation of the business of the Company or its Subsidiaries. Since July 21, 2021, the Company and its Subsidiaries (ivA) any regulatory or self-regulatory entityhave, in each caseall material respects, alleging that any Processing implemented and maintain complete, accurate and up to date records of responses to requests from individuals requesting access, rectification or deletion of Personal Data by Information or on behalf other exercise of a Group rights under Company is in violation Privacy Commitments and (B) have responded to all requests from individuals requesting access, rectification, deletion or other exercise of any applicable rights under Privacy Laws, in the time period and in accordance in all material respects with the other requirements of Company Privacy Commitments.
(c) Since All Personal Information processed by the Lookback Date, (i) there Company or its Subsidiaries has been no collected fairly and lawfully (including through the provision of information notices and other disclosures (in the Company Privacy Policies or otherwise) and the collection of valid consent where required) and can be used legitimately in the manner used by the Company without breaching any Company Privacy Commitments. The Company and its Subsidiaries have, as of the date hereof and since July 21, 2021, posted and prominently made available on its websites, mobile applications and other mechanisms through which the Company or its Subsidiaries collects Personal Information, a Company Privacy Policy in conformance in all material unauthorized accessrespects with Privacy Laws. All Company Privacy Policies published by the Company are and, usesince July 21, acquisition or disclosure 2021, have, in all material respects, been accurate, complete and consistent with the actual practices of the Company and its Subsidiaries with respect to the processing of Personal DataInformation. As of the date hereof, no disclosure or confidential business information representation made or contained in any Company Privacy Policy published by the possession Company has been intentionally inaccurate, misleading, deceptive or control in violation of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and Privacy Laws (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced including by containing any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Dataomission).
(d) Each Group The Company owns and its Subsidiaries have in place written Contracts with all of their customers regarding the Company’s or has its Subsidiaries’ processing of Personal Information on behalf of such customers. Such Contracts include written obligations that comply with the requirements of Privacy Laws in relation to the Company’s and its Subsidiaries’ processing and protection of Personal Information. When acting as a license to use Data Processor on behalf of customers, the Company IT Systems as necessary and its Subsidiaries do not process Personal Information for any purpose except on the instruction of the customer (unless required to operate do so by applicable Law). Neither the business Company nor its Subsidiaries have transferred or permitted the transfer of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included Personal Information originating in the European Economic Area (“EEA”) or United Kingdom (“UK”) to outside the EEA or UK (as applicable), or otherwise across jurisdictional borders, except where such transfers have complied with the requirements of the Company IT SystemsPrivacy Commitments and with reasonable safeguards in place for such transfer.
(e) The Group Companies Where the Company or its Subsidiaries use a Data Partner to process Personal Information or otherwise share or disclose Personal Information with such Data Partner, there is in existence a Contract. Such Contract with the Data Partner includes written obligations in relation to the processing and protection of Personal Information and has agreed to comply with those obligations in a manner sufficient for the Company’s and its Subsidiaries’ compliance with Company Privacy Commitments, including where applicable, obligations for any party acting as a Data Processor (as defined under the Privacy Laws) to act only on the instructions of the Data Controller (as defined under the Privacy Laws) and such other terms as are and have been in compliance in all material respects with all applicable required under Privacy and Security Requirements since Laws. To the Lookback DateKnowledge of the Company, no Data Partner has breached any such Contracts.
(f) The Group Companies Company and its Subsidiaries have, and have required all Data Partners to have, implemented reasonable physicaladministrative, physical and technical and administrative safeguards to protect and maintain the privacy, operation, confidentiality, integrity integrity, availability and security of Personal Information and any information technology systems owned by the Company or its Subsidiaries against any accidental, unlawful or unauthorized use, access, disclosure, modification, destruction, loss, or compromise or other processing (a “Security Incident”). The Company and its Subsidiaries use, and have at all times used, reliable methods designed to ensure the correct identity of the users of those with access to any information technology systems owned by the Company or its Subsidiaries, and have used reliable measures designed to protect the security and integrity of transactions executed through the IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorsCompany or its Subsidiaries.
(g) In relation to any Security Incident and/or violation of Company Privacy Commitments, neither the Company, any Subsidiary, nor to the Knowledge of the Company, as of the date hereof, any Data Partner has:
(i) notified in writing, or been required to notify in writing, any customer, consumer, employee, Governmental Authority or other Person or (ii) received any written notice, inquiry, request, claim, complaint, correspondence or other communication from, or been the subject of any investigation or enforcement action by, any Governmental Authority or other Person. To the Knowledge of the Company, as of the date hereof, there are no facts or circumstances that would give rise to the occurrence of (i) or (ii).
Appears in 1 contract
Data Privacy and Security. (a) Each Group Except as set forth on Section 3.22(a) of the Company does not knowingly collect or process Personal Data contrary to lawDisclosure Schedule, to the Company and each Group Company’s knowledge. The Company has safeguards of its Subsidiaries have implemented and followed in place all material respects commercially reasonable physical, technical, organizational, and administrative security measures, policies, and procedures that are sufficient designed to: (i) mitigate potential security risks with respect to protect Personal Data and confidential information in the Company’s possession services; (ii) comply with the Data Privacy Requirements, (iii) identify security breach risks relating to the Company’s information technology systems, (iv) prevent security breaches, (v) identify, document, and remediate actual or control from unauthorized access by third Persons suspected security breaches relating to the Company’s information technology systems and to ensure that the operation Company’s services, and (vi) at least annually, train all employees, consultants, agents, and contractors of the businesses Company and each of each Group Company its Subsidiaries applicable to their service to the Company, in (including with respect A) their responsibilities relating to employee matters) are in compliance with all Data Privacy Requirements, and Security Requirements in all material respects(B) recognizing and minimizing security breach risks relating to the Company’s information technology systems, the Company’s services, and any customer data held by the Company and each of its Subsidiaries.
(b) There are no pending ProceedingsNo complaint, nor claim, enforcement action, or litigation that alleges any non-compliance by the Company or any of its Subsidiaries with any applicable Data Privacy Requirement has there been served on or, to the Knowledge of the Company, initiated against the Company or any Proceedings against of its Subsidiaries and the Company and each of its Subsidiaries have not received any Group Company initiated by (i) subpoenas, demands, or other written notices from any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity investigating, inquiring into, or (iv) otherwise relating to any regulatory actual or self-regulatory entity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company is in alleged violation of any applicable Data Privacy LawsRequirement and, to the Knowledge of the Company, the Company and each of its Subsidiaries are not under investigation by any Governmental Entity for any actual or potential violation of any Data Privacy Requirement.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure The Company and each of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies its Subsidiaries have not experienced any material successful unauthorized access to, use security breaches within the past three (3) years that would require law enforcement or modification ofGovernmental Entity notification, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice remedial action under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.Privacy
Appears in 1 contract
Sources: Merger Agreement (Diligent Corp)
Data Privacy and Security. (a) Each The Company has not received any written notice of any pending or threatened Proceeding against or involving any Group Company does not knowingly collect or process Personal Data contrary to lawor, to each the Company’s Knowledge, any Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company Affiliates initiated by (i) any Person; (ii) the United States Federal Trade Commission, including any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each caseEntity, alleging that any Processing of Personal Data by or on behalf of a any Group Company or its Affiliates is or was in violation of any applicable Privacy LawsRequirements.
(b) The Group Companies take, in the reasonable determination of the Company’s management team, commercially reasonable measures designed to protect and maintain (i) the ownership and confidentiality of their material proprietary Company Intellectual Property and (ii) the security, confidentiality, continuous operation and integrity of their Company IT Systems (and all confidential data and Protected Data stored therein or transmitted thereby). The Group Companies have back-up and disaster recovery arrangements for the continued operation of their business in the event of a failure of its Company IT Systems that are, in the reasonable determination of the Company’s management team, commercially reasonable and in accordance with standard industry practice.
(c) Since To the Lookback DateCompany’s Knowledge, there have been no unauthorized intrusions or breaches of security that has resulted in unauthorized use of, or access to, the Company IT Systems or Protected Data that, pursuant to any applicable Law, would require the Company or a Subsidiary to notify customers or employees of such breach or intrusion.
(d) Except as would not, individually or in the aggregate, have, or be reasonably expected to result in, a Company Material Adverse Effect, (i) there has not been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information any Data Breach with respect to any Protected Data in the possession or control of any Group Company oror its Affiliates, or any of its contractors with regard to the Company’s knowledge, any third party service provider Protected Data obtained from or on behalf of any Group CompanyCompany or its Affiliates, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date or Protected Data, and (iii) none of the Group Companies is aware nor their Affiliates have been notified or been required to notify any Person of any written or(a) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authorityb) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT SystemsBreach.
(e) The Group Companies are Company’s and have been in compliance its Subsidiaries’ collection, use, disclosure, storage and transfer of Personal Data complies in all material respects with all Privacy Requirements. The execution, delivery and performance of the transactions contemplated by this Agreement do not materially violate the Company’s privacy policy as it currently exists or, to the extent any previous privacy policy of the Company remains applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession maintained by the Company or control from unauthorized access by any Personits Subsidiaries, including each of the Group Companies’ employees and contractorsas such previous privacy policy existed before.
Appears in 1 contract
Sources: Business Combination Agreement (AlphaVest Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to lawis, to each Group Company’s knowledge. The Company and has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are been since June 1, 2018 in compliance with all Privacy and Security Requirements in all material respectsrespects with HIPAA and within a reasonable time thereafter through the present was materially complaint with all applicable Privacy Laws (“Privacy Compliance Dates”).
(b) There The Group Companies have complied with and are no in material compliance with all applicable Privacy Obligations. The Group Companies have adopted and published privacy notices and policies that accurately describe their privacy practices, and they have complied and are in compliance with those notices and policies. The Group Companies have contractually obligated all third parties Processing Personal Data on their behalf to comply with applicable Privacy Obligations. The execution, delivery, performance and consummation of the transaction contemplated hereunder (including the Processing of Personal Data in connection therewith) comply with the Group Companies’ applicable privacy notices and policies and with all applicable Privacy Obligations.
(c) The Group Companies have implemented and maintain a written information security program comprising reasonable administrative, physical, and technical safeguards that are designed to protect against unauthorized access to or use of or loss of access to the Group Companies’ internal computer systems (the “Company Systems”) or the Group Companies’ Sensitive Data, and consistent with the Group Companies’ Privacy Obligations, and any written contractual commitment made by the Group Companies related to privacy or information security.
(d) Each Group Company has completed a security “risk analysis” (as required by 45 C.F.R. § 164.308(a)(1)(ii)(A)) in compliance with HIPAA at least once every 12 months since the requirement to perform such a security risk analysis first became applicable to it.
(e) The Company has not received notice of any claims, investigations, or pending Proceedings, nor has there been any material Proceedings against any Group Company Company, initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityEntity, in each case, alleging that any Processing violations of Laws or other Privacy Obligations with respect to Personal Data possessed by or on behalf of a any Group Company is in violation of any applicable Privacy LawsCompany.
(cf) Since the Lookback DateThere have not been any incidents of, or third party claims, since June 1, 2018, alleging, (i) there has been no material Security Breaches, (ii) unauthorized access, use, acquisition access to or disclosure use of Personal Dataor loss of access to as a result of any actions by an unauthorized party any of the Company Systems or other technology necessary for the operations of the business, or confidential business information in the possession (iii) any unauthorized access or control acquisition of any Sensitive Data maintained by the Group Company or, to the Company’s knowledge, Companies or by any third party service provider on behalf of any Group Company. No Group Company has notified in writing, or been required by applicable Law, Governmental Entity or other Privacy Obligation to notify in writing, any Person or Governmental Entity of any Security Breach. No Group Company has received any notice of any claims, investigations (including investigations by a Governmental Entity), or alleged violations of Laws or other Privacy Obligations with respect to Personal Data possessed by any Group Company. No Group Company has had a “breach” as defined by HIPAA of unsecured protected health information (as defined under HIPAA) and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of extent that any Group Company systems networks, communication equipment or other technology necessary for the operations has had a “breach” as defined by HIPAA of the unsecured protected health information (as defined under HIPAA) such Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date has reported each such breach as required by applicable contracts and none of the Group Companies is aware of any written or, Law to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any all applicable Persons and Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataEntities.
(dg) Each Group Company owns or has current and valid Business Associate Agreements with each business associate of the applicable entity that is a license to use the Company IT Systems Business Associate (as necessary to operate the business of each such terms are defined by HIPAA). Since June 1, 2018, no Group Company as currently conducted. The Group Companies have has received written notice of a sufficient number “breach” under the Privacy Laws or a material breach of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access contractual obligations by any PersonBusiness Associate. Since June 1, including each of the 2018, no Business Associate has breached in any material respect any Business Associate Agreement or other data privacy or security contractual obligations between a Business Associate and a Group Companies’ employees and contractorsCompany.
Appears in 1 contract
Data Privacy and Security. (a) Each Except as would not reasonably be expected to be material to the Group Company does not knowingly collect or process Personal Data contrary to lawCompanies, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of taken as a whole, each Group Company has, (including i) for the past three (3) years, complied with respect applicable Privacy Obligations; and (ii) implemented and complied with an appropriate data protection compliance program and appropriate written policies and procedures relating to employee matters) are the Processing of Personal Data as and to the extent necessary in compliance order to comply with all Privacy Obligations (“Privacy and Data Security Requirements Policies”). The Group Companies have adopted and published privacy notices and policies that describe their privacy practices to their websites, mobile applications or other electronic platforms and complied with those notices and policies, except where non-compliance would not reasonably be expected to have, individually or in the aggregate, a Company Material Adverse Effect. The Group Companies have implemented an information security program that, as of the date of this Agreement and as of the Closing Date, is comprised of commercially reasonable and appropriate physical, technical, organizational and administrative security measures and policies and that complies with all material respectsPrivacy Obligations and that is reasonably designed to protect and maintain the privacy, security and integrity of any Personal Data, confidential information or trade secrets in their possession or under their control, or otherwise Processed by such Group Companies, including to protect such data from any Security Breaches.
(b) There are For the past three (3) years, no Group Company has received written notice of any pending Proceedings, nor nor, to the knowledge of the Company, has there been any Proceedings against any Group Company initiated by by: (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityEntity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group Company Company: (A) is in violation of any applicable Privacy LawsObligations; or (B) is in violation of any Privacy and Data Security Policies.
(c) Since For the Lookback Date, past three (3) years no Group Company has (i) there has been no material unauthorized accessreceived any written notice, userequest, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment correspondence or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced communication from any material successful unauthorized access toSupervisory Authority, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices been subject to any investigation or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person enforcement action (including any Governmental Entity fines or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.other sanctions),
Appears in 1 contract
Sources: Business Combination Agreement (Sandbridge Acquisition Corp)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process has implemented adequate written policies relating to the Processing of Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons as and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all extent required by applicable Privacy and Security Requirements in all material respectsRequirements.
(b) There are is (and since January 1, 2018 there has been) no material Proceeding pending Proceedingsor, nor has there been any Proceedings to the Company’s knowledge, threatened against any Group Company initiated by any Person (including (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; , (iiiii) any other Governmental Entity Entity, foreign or domestic or (iviii) any regulatory or self-regulatory entity, in each case, ) alleging that any Processing of Personal Data by or on behalf of a Group Company is or was in violation of any applicable Privacy Lawsand Security Requirements, nor, to the Company’s knowledge, is there (nor since January 1, 2018 has there been) a reasonable basis for the foregoing.
(c) Since the Lookback DateTo Company’s knowledge, since January 1, 2018, (i) there has been no material unauthorized accessSecurity Incidents with respect to any Company IT Systems, use, acquisition or disclosure of Personal Data, or Company Products, (ii) there has been no unauthorized access to, or use, disclosure, or Processing of Personal Data or any trade secrets, know-how or material confidential business information of or in the possession or control of any Group Company or, or any of its contractors with regard to the Company’s knowledge, any third party service provider Personal Data obtained from or on behalf of any a Group Company, and (iiiii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware has notified or been required to notify any Person of any written or(A) loss, to the knowledge of the Companytheft or damage of, oral notices or complaints from any Person regarding such a Security Breach (B) other unauthorized or incident. None of the Group Companies has received any written complaintsunlawful access to, claimsor use, demands, inquiries disclosure or other noticesProcessing of, including a notice of investigationPersonal Data, from any Person (including any Governmental Entity except, in each case, as is not and would not reasonably be expected to be, individually or self-regulatory authority) regarding any of in the aggregate, material to the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Datataken as a whole.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have taken reasonable precautions to protect the confidentiality, integrity and security of the Company IT Systems and all information stored or contained therein or transmitted thereby from any loss, theft, or unauthorized disclosure, use, access, interruption or modification by any Person. To Company’s knowledge, all Company IT Systems are (i) free from any Malicious Code, material defect, bug or programming, design or documentation error and (ii) in sufficiently good working condition to effectively perform all material information technology operations necessary for the operation of the Business (except for ordinary wear and tear). Since January 1, 2018, there have not been any material failures, breakdowns or continued substandard performance of any Company IT Systems that have caused a sufficient number material failure or disruption of license seats for all Software included in the Company IT Systems. The Group Companies have implemented, maintained and tested adequate and commercially reasonable disaster recovery procedures and facilities for the Business and all Data material to the respective businesses of the Group Companies has been regularly backed-up in an encrypted manner and tested for restoration.
(e) The Group Companies are (i) engage and have been engaged in, directly or indirectly, Data Processing only with respect to such Data as they are authorized to so engage (or to cause such Processing, as applicable) by Law and, as applicable, Contract, except as is not and would not reasonably be expected to be, individually or in compliance the aggregate, material to the Group Companies, taken as a whole, and (ii) have implemented reasonable safeguards designed to prevent unauthorized use or disclosure of such Data. The Group Companies have, with respect to all such Data that is subjected to any Processing directly or indirectly by the Group Companies in the course of operating the Business, all rights necessary to conduct the operation of the Business as then-currently conducted, in all material respects with all applicable Privacy and Security Requirements since the Lookback Daterespects.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Business Combination Agreement (Tailwind Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process has implemented commercially reasonable practices, procedures and policies designed to address the security and privacy of Personal Data contrary to law, to Processed by each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each such Group Company to the extent required by applicable Law (including “Privacy and Data Security Policies”) and such Privacy and Data Security Policies comply with respect to employee matters) are all applicable Privacy Laws in compliance all material respects. Each Group Company complies in all material respects with all applicable Privacy Laws and with all Privacy and Data Security Requirements in all material respectsPolicies.
(b) There are no The Company has not received notice of any pending Proceedings, nor to the Company’s knowledge has there been any material Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity foreign or domestic; or (iv) any regulatory or self-regulatory entityentity that, in each casecase of (i) to (iv), alleging allege that any Processing of Personal Data by or on behalf of a Group Company (A) is in violation of any applicable Privacy LawsLaws or (B) is in violation of any Privacy and Data Security Policies.
(c) Since the Lookback DateJanuary 1, 2018, (i) there has been no material instance of unauthorized access, use, acquisition use or disclosure of Personal Data, or confidential business information Data in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written orand, to the knowledge of the Company, oral notices any of its contractors with regard to any Personal Data obtained from or complaints from on behalf of a Group Company and
(ii) there have been no material unauthorized intrusions or breaches of security into any Person regarding such a Security Breach or incident. None Company IT Systems.
(d) Each of the Group Companies has received any written complaintsestablished and complied in all material respects with its information security practices, claimsprocedures, demandsand policies, inquiries which include commercially reasonable measures such as back-ups, disaster recovery and administrative, technical, and physical safeguards designed to safeguard the security, confidentiality, integrity and availability of Company IT Systems and Personal Data in its possession, custody, or other noticesunder its control, including a notice of investigationagainst loss, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Datetheft, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach misuse or unauthorized access to Processing, access, use, modification or use of any Company IT System or Personal Data.
(d) disclosure. Each Group Company owns or has a license or right to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects with all applicable Privacy and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractors.
Appears in 1 contract
Sources: Business Combination Agreement (Consonance-HFW Acquisition Corp.)
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Leading Group Company Companies is and during the last five (including with respect to employee matters5) are years has been in compliance with all Privacy and Security Requirements in all material respectsrespects with all applicable cybersecurity, data security and personal information protection Laws and contractual obligations binding upon such Leading Group Company relating to the receipt, collection, compilation, use, storage, processing, sharing, safeguarding, security, disposal, destruction, disclosure or transfer of personal data, including any applicable Laws relating to transferring personal information and other data outside of the PRC.
(b) There are no As of the date of this Agreement, the Company has not received notice of any pending ProceedingsAction, nor has there been any Proceedings material Action against any Leading Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general general, Ministry of Industry and Information Technology of the PRC (including its local counterparts) or similar state officialofficial or any other Governmental Authority (whether in the United States, Cayman Islands or PRC); or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityAuthority, in each case, alleging that any Processing processing of Personal Data personal data by or on behalf of a member of the Leading Group Company Companies is in violation of any applicable Privacy Lawsrequirements under Section 3.33(a).
(c) Since During the Lookback Date, last five (5) years (i) there has been no material unauthorized access, use, acquisition or disclosure processing of Personal Data, or confidential business information personal data in the possession or control of any Leading Group Company oror any service providers thereto, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no material unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since IT systems under the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use control of any Leading Group Company IT System and (iii) no Leading Group Company has experienced any security risk or Personal Dataincident that triggers the breach notification obligation under the applicable cybersecurity, data security and personal information protection Laws or has actually made such breach notification.
(d) Each Leading Group Company owns or has a license binding Contract in place to use the Company IT Systems systems as necessary to operate the its business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for conducted in all Software included in the Company IT Systemsmaterial respects.
(e) The Each Leading Group Companies Company has implemented and established data safeguards against the destruction, loss, damage, corruption, alteration, loss of integrity, commingling or unauthorized access, acquisition, use, disclosure or other processing of personal data that are consistent with industry standards and have been in compliance the requirements of applicable Law in all material respects with respects. Each Leading Group Company maintains backups of all applicable Privacy and Security Requirements since data used to conduct the Lookback Date.
(f) The business of such member of the Leading Group Companies have implemented at a reasonable physical, technical and administrative safeguards to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Person, including each of the Group Companies’ employees and contractorsfrequency.
Appears in 1 contract
Sources: Business Combination Agreement (Healthcare AI Acquisition Corp.)
Data Privacy and Security. (a) Each Group The Company does not knowingly collect or process Personal Data contrary Group, and to law, to each Group the Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data , its Third Party Service Providers, have been at all times and confidential information in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are remain in compliance with all Privacy and Security Requirements in all material respectsrespect with all applicable Privacy Laws. No Company Group Member’s externally-facing privacy policies or notices contain any material omissions or are misleading or deceptive in any material respect.
(b) There are no is not currently pending Proceedingsor, nor to the Company’s knowledge, threatened, and there has there not at any time in the past three (3) years been any Proceedings any, Proceeding against any Company Group Company Member initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iiiii) any other Governmental Entity Entity, foreign or domestic; (iii) any regulatory entity, privacy regulator or otherwise, or (iv) any regulatory or self-regulatory entityother Person, in each case, alleging that any with respect to privacy, cybersecurity, or the Processing of Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback DateInformation, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company orand, to the Company’s knowledge, there are no facts upon which such a Proceeding could be based.
(c) There have not been any third party service provider on behalf of any Group Companyactual, and (ii) suspected, or alleged material Security Incidents or actual or alleged claims related to material Security Incidents, and, to the Company’s knowledge, there have been are no unauthorized intrusions into facts or Security Breaches of circumstances which could reasonably serve as the basis for any Group Company systems networkssuch allegations or claims. There are no data security, communication equipment information security, or other technology necessary for technological vulnerabilities with respect to the operations of Company Group’s services or with respect to the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices that would have a materially adverse impact on their operations or complaints from any Person regarding such cause a material Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataIncident.
(d) Each The Company Group Company owns Members own or has a have license to use pursuant to a Material Contract the Company IT Systems as necessary to operate the business Business as currently conducted and such Company IT Systems are sufficient for the operation of each Group Company the Business as currently conducted. The Company Group Companies Members have back-up and disaster recovery arrangements, procedures and facilities for the continued operation of its businesses in the event of a sufficient number failure of license seats for all Software included in the Company IT SystemsSystems that are, in the reasonable determination of the Company, commercially reasonable and in accordance in all material respects with standard industry practice. In the last three (3) years, there has not been any material disruption, failure or, to the Company’s knowledge, unauthorized access with respect to any of the Company IT Systems that has not been remedied, replaced or mitigated in all material respects. To the Company’s knowledge, none of the Company IT Systems contain any worm, bomb, backdoor, trap doors, Trojan horse, spyware, keylogger software, clock, timer or other damaging devices, malicious codes, designs, hardware component, or software routines that causes the Company Software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized person.
(e) The Company Group Companies are Members have, and in the last three (3) years have been had, in compliance in all material respects with all applicable Privacy place reasonable and Security Requirements since the Lookback Date.
(f) The Group Companies have implemented reasonable physicalappropriate administrative, technical technical, physical and administrative organizational measures and safeguards to (i) ensure the integrity, security, and the continued, uninterrupted, and error-free operation of the Company IT Systems, and the confidentiality of the source code of any Company Software, and (ii) to protect Personal Information and other Business Data against loss, damage, and unauthorized access, use, modification, or other misuse (“Misuse”). Without limiting the privacygenerality of the foregoing, operation, confidentiality, integrity the Company Group’s information security program (i) identifies internal and external risks to the security of the Personal Information, Business Data, services and Company IT Systems; and (ii) implements, monitors and improves adequate and effective safeguards to control those risks. The Company Group has timely and reasonably remediated and addressed, or is in the process of remediating and addressing in accordance with industry standards, any and all audit or security assessment findings relating to its implementation of administrative, technical, and physical security measures. Each Company Group employee has received training regarding information security that is relevant to each such employee’s role and responsibility within the business and such employee’s access to Personal Information, Business Data and Company IT Systems. All Company IT Systems and Personal Data in their possession any data stored therein are recorded, stored, maintained or operated, or otherwise are wholly dependent, on facilities which are under the exclusive ownership or control from unauthorized access by any Person, including each of the Company Group Companies’ employees and contractors(other than with respect to Third Party Service Providers, Leased Real Property or a public blockchain).
Appears in 1 contract
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient implemented and maintains commercially reasonable written policies relating to protect (i) the Processing of Personal Data to the extent required by applicable Privacy Law (“Privacy and confidential information Data Security Policies”) and (ii) other Data Security Requirements. The conduct of the Business is (and has in the Company’s possession or control from unauthorized access by third Persons and to ensure that the operation of the businesses of each Group Company past three (including with respect to employee matters3) are years been) in material compliance with all Privacy and Data Security Requirements in all material respectsRequirements.
(b) There are no Since December 31, 2020, the Company has not received written notice of any pending Proceedings, nor has there been any Proceedings against any Group the Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; or (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entityEntity, in each case, alleging that any Processing of Personal Data by or on behalf of a Group the Company is in violation of any applicable Privacy LawsData Security Requirements.
(c) Since December 31, 2020, to the Lookback DateCompany’s Knowledge, (i) there has been no material actual, suspected, or alleged unauthorized or unlawful access, use, acquisition loss, disclosure or disclosure other Processing of Personal Data, Data or confidential business information trade secrets in the possession or control of any Group the Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no actual, suspected, or alleged unauthorized intrusions or breaches of security into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal DataSystems.
(d) Each Group The Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group the Company as currently conducted. The Group Companies Company IT Systems are sufficient and in good working condition for the operation of the Business, including as to capacity, scalability, and ability to process current and anticipated peak volumes in a timely manner. Since December 31, 2020, there have been no failures, continued substandard performance or other adverse events affecting any Company IT Systems that have caused any material disruption or interruption in the use of any Company IT Systems or the conduct of the Business. The Company has taken reasonable precautions to protect the confidentiality, integrity and security of the Company IT Systems and Personal Data stored or contained therein or transmitted or Processed thereby from any theft, corruption, loss or unauthorized use, access, interruption or modification or other Processing by any Person. The Company maintains commercially reasonable security plans, procedures and facilities, and acts in material compliance therewith. The Company has purchased a sufficient number of license seats (and scope of rights) for all third-party Software included that is used or held for use in the conduct of the Business, and the Company IT Systems.
(e) The Group Companies are and have been in compliance has complied in all material respects with all applicable Privacy the terms and Security Requirements since conditions of the Lookback Date.
(f) The Group Companies have implemented reasonable physical, technical and administrative safeguards agreements corresponding to protect the privacy, operation, confidentiality, integrity and security of all Company IT Systems and Personal Data in their possession or control from unauthorized access by any Personsuch Software, including each with respect to the use of such Software in the conduct of the Group Companies’ employees and contractorsBusiness.
Appears in 1 contract
Data Privacy and Security.
(a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company is in compliance and has safeguards in place that are sufficient complied with all applicable Privacy Laws, except where such failure to protect Personal Data and confidential information comply, individually or in the Company’s possession or control from unauthorized access by third Persons aggregate, has not had and would not reasonably be expected to ensure that the operation of the businesses of each Group have a Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respectsMaterial Adverse Effect.
(b) The Company has in place policies and procedures for the proper collection, processing, transfer, disclosure, sharing, storing, security and use of Personal Information that comply with Privacy Laws.
(c) There are is no currently pending Proceedingsor, nor to the Company’s knowledge, threatened, and there has there not been any Proceedings any, Action against any Group the Company or its Subsidiaries initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iiiii) any other Governmental Entity Entity, foreign or domestic; (iii) any regulatory entity, privacy regulator or otherwise, or (iv) any regulatory or self-regulatory entityother Person, in each case, alleging that any Processing of with respect to privacy, cybersecurity, or Personal Data by or on behalf of a Group Company is in violation of any applicable Privacy LawsInformation.
(cd) Since There have not been any actual, suspected, or alleged material Security Incidents or actual or alleged claims related to material Security Incidents, and, to the Lookback DateCompany’s knowledge, there are no facts or circumstances which could reasonably serve as the basis for any such allegations or claims. There are no data security, information security, or other technological vulnerabilities with respect to the Company’s or its Subsidiaries’ services or with respect to the Company IT Systems that would have a materially adverse impact on their operations or cause a material Security Incident. To the Company’s knowledge, no circumstance has arisen in which Privacy Laws would require the Company to notify a Person or Governmental Entity of a data security breach or Security Incident.
(ie) there has been no material unauthorized accessThe Company and its Subsidiaries own, or have license to use, acquisition pursuant to a Contract of the Company or disclosure its Subsidiaries, respectively, the Company IT Systems as necessary to operate their respective businesses as currently conducted and such Company IT Systems are sufficient for the operation of Personal Datatheir respective businesses as currently conducted. The Company and its Subsidiaries have back-up and disaster recovery arrangements, or confidential business information procedures and facilities for the continued operation of its businesses in the possession or control event of a failure of the Company IT Systems that are, in the reasonable determination of the Company, commercially reasonable and in accordance in all material respects with standard industry practice. There has not been any Group Company material disruption, failure or, to the Company’s knowledge, unauthorized access with respect to any third party service provider on behalf of any Group Companythe Company IT Systems that has not been remedied, and (ii) to replaced or mitigated in all material respects. To the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for all Software included in contain any worm, bomb, backdoor, trap doors, Trojan horse, spyware, keylogger software, clock, timer or other damaging devices, malicious codes, designs, hardware component, or software routines that causes the Company IT Systems.
(e) The Group Companies are and have been in compliance in all material respects Software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with all applicable Privacy and Security Requirements since the Lookback Datepassage of time or upon command by any unauthorized person.
(f) The Group Companies Company and its Subsidiaries have, and have implemented had, in place commercially reasonable physicaland appropriate administrative, technical technical, physical and administrative safeguards organizational measures and safeguards, in compliance with all data security requirements under Privacy Laws, to protect (i) ensure the privacyintegrity, operationsecurity, confidentialityand the continued, integrity uninterrupted, and security error-free operation of all the Company IT Systems Systems, and Personal Data in their possession or control from unauthorized access by any Person, including each the confidentiality of the Group Companies’ employees and contractors.source code of any Company Software,
Appears in 1 contract
Sources: Merger Agreement
Data Privacy and Security. (a) Each Group Company does not knowingly collect or process Personal Data contrary to law, to each Group Company’s knowledge. The Company has safeguards in place that are sufficient to protect Personal Data and confidential information in To the Knowledge of the Company’s possession or control from unauthorized access by third Persons , the Company and to ensure that the operation of the businesses of each Group Company (including with respect to employee matters) are in compliance with all Privacy and Security Requirements in all material respects.
(b) There are no pending Proceedings, nor has there been any Proceedings against any Group Company initiated by (i) any Person; (ii) the United States Federal Trade Commission, any state attorney general or similar state official; (iii) any other Governmental Entity or (iv) any regulatory or self-regulatory entity, in each case, alleging that any Processing of Personal Data Information by or on behalf of a Group Company is in violation of any applicable Privacy Laws.
(c) Since the Lookback Date, (i) there has been no material unauthorized access, use, acquisition or disclosure of Personal Data, or confidential business information in the possession or control of any Group Company or, to the Company’s knowledge, any third party service provider on behalf of any Group Company, and (ii) to the Company’s knowledge, there have been no unauthorized intrusions into or Security Breaches of any Group Company systems networks, communication equipment or other technology necessary for the operations of the Group Companies’ business. The Group Companies have not experienced any material successful unauthorized access to, use or modification of, or interference with Company IT Systems since the Lookback Date and none of the Group Companies is aware of any written or, to the knowledge of the Company, oral notices or complaints from any Person regarding such a Security Breach or incident. None of the Group Companies is and has received any written complaints, claims, demands, inquiries or other notices, including a notice of investigation, from any Person (including any Governmental Entity or self-regulatory authority) regarding any of the Group Companies’ Processing of Personal Data or compliance with applicable Privacy and Security Requirements. Since the Lookback Date, none of the Group Companies have provided or have been obligated to provide notice under any Privacy and Security Requirements to regarding any Security Breach or unauthorized access to or use of any Company IT System or Personal Data.
(d) Each Group Company owns or has a license to use the Company IT Systems as necessary to operate the business of each Group Company as currently conducted. The Group Companies have a sufficient number of license seats for at all Software included in the Company IT Systems.
(e) The Group Companies are and have times been in compliance in all material respects with all applicable Privacy and Security Data Requirements. The Company has not received any written communication regarding any actual or suspected violation of any Data Requirements. No Action against the Company, or any audit or other investigation of the Company, by any Governmental Entity under any Data Requirements since has occurred, is pending or, to the Lookback DateCompany’s Knowledge, is threatened.
(fb) The Group Companies have implemented reasonable physicalExcept as set forth on Disclosure Schedule 2.24(b), technical the Company has established and administrative safeguards has at all times maintained and, to protect the Knowledge of the Company, complied in all material respects with all policies regarding the confidentiality, nondisclosure, privacy, operation, confidentiality, integrity and security of all data and information Processed by or on behalf of the Company IT Systems (“Company Data”) as required by all Data Requirements. The Company has obtained all applicable consents, permissions and authorizations required by all Data Requirements with respect to all Company Data and the Processing thereof. Without limiting the foregoing, the Company has entered into a valid and enforceable business associate agreement (as defined under HIPAA) with its Affiliated Practices, as applicable. To the Knowledge of the Company, the Company has entered into such other Contract as may be required under any Data Requirements in all instances in which the Company has processed Personal Data in their possession Information of, for, or control from unauthorized access by on behalf of any Person, including each and in all instances in which any Person has processed Personal Information for or on behalf of the Group Companies’ employees Company, that in each instance, to the Knowledge of the Company, complies with all Data Requirements.
(c) Since January 1, 2018, the Company has not notified, and, to the Knowledge of the Company, there have been no facts or circumstances that would require the Company to notify, any Governmental Entity or other Person of any Security Incident.
(d) Following the Closing, the Company will retain and contractorshave all consents, permissions and authorizations necessary to Process all Company Data in the same manner and to the same extent the Company Data was Processed by and on behalf of Company prior to the Closing. The Transactions will not cause, constitute, or result in a breach or violation of any applicable Data Requirements.
Appears in 1 contract
Sources: Equity Interest Purchase Agreement (U S Physical Therapy Inc /Nv)