Data Privacy and Security. (a) Since January 1, 2018, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo and its Subsidiaries of any Personal Data are and have been in compliance in all material respects with the Privacy Requirements, except where any instances of non-compliance have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. (b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. (c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries. (d) To the Knowledge of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer that, to the Knowledge of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiaries. (e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 2 contracts
Sources: Agreement and Plan of Merger (Livongo Health, Inc.), Merger Agreement (Teladoc Health, Inc.)
Data Privacy and Security. (a) Since January 1, 2018, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo and its Subsidiaries of any Personal Data The IT Systems are and have been in compliance sufficient in all material respects with for the Privacy Requirementsoperation of the Company as currently conducted. The Company has implemented commercially reasonable administrative and technical safeguards designed to protect the integrity, except where any instances security and confidentiality of non-compliance have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo all material confidential information concerning the Company and its Subsidiaries maintain commercially reasonable policiesbusiness, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of including any Personal Data Information stored in the IT Systems against loss, theft, misuse or Tempranillo’s unauthorized access, use, modification, alteration, destruction or its Subsidiaries’ business data by any Third Partydisclosure. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not not, individually or in the aggregate, reasonably be expected to have a Tempranillo Material Adverse Effectmaterial adverse effect on the Company, to Tempranillo’s Knowledgetaken as a whole, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 20182023, there have not malfunctioned been no unauthorized intrusions or failed (except for malfunctions breaches of the security of the IT Systems, or failures that have been fully remedied) of the IT Systems. The Company has implemented and (iii) are free from bugs maintained commercially reasonable disaster recovery procedures for all confidential information concerning the Company and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Softwareits business. Except as would not not, individually or in the aggregate, reasonably be expected to have a Tempranillo Company Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 20182023, no Person the Company has gained unauthorized access taken commercially reasonable steps to implement security patches and upgrades that are generally available for the IT Assets owned by, or used and controlled by, Tempranillo and its SubsidiariesSystems.
(db) To The Company has taken commercially reasonable steps to require that any third party with access to Personal Information collected by or on behalf of the Knowledge Company has implemented and maintained commercially reasonable administrative and technical safeguards designed to protect the integrity, security and confidentiality of Tempranillosuch Personal Information.
(c) The Company is, Tempranillo and its Subsidiaries since January 1, 2023, has been, in compliance with all applicable Data Protection Requirements, except for any noncompliance that would not, individually or in the aggregate, reasonably be expected to have executed current and valid Business Associate Agreements with each (i) customer thata material adverse effect on the Company, taken as a whole. Except as would not, individually or in the aggregate, reasonably be expected to have a material adverse effect on the Company, taken as a whole, since January 1, 2023, there have been no breaches, violations, outages, security incidents, unauthorized uses, transfer, destruction, disclosures, losses, thefts, ▇▇▇▇▇▇ demands, alterations of or access to Personal Information maintained by or, to the Knowledge of Tempranillothe Company, on behalf of the Company that would require notification of individuals, law enforcement or any Governmental Authority under applicable Data Protection Law. Since January 1, 2023, until the date hereof, the Company has not received written communication (including from any Governmental Authority) that alleges that the Company is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are not in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its SubsidiariesData Protection Laws.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Sources: Merger Agreement (Evoke Pharma Inc)
Data Privacy and Security. (a) Since January 1, 2018, The operation of the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo and its Subsidiaries of any Personal Data are and have been in compliance in all material respects with the Privacy Requirements, except where any instances of non-compliance have not hadAcquired Business complies, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 20182022, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) has complied, in all material respects, with applicable Information Privacy and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious SoftwareSecurity Requirements. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effectexpected, individually or in the aggregate, to Tempranillo’s Knowledgebe material to the Acquired Business, neither PepsiCo nor any of its Affiliates has, since January 1, 20182022, no (A) experienced any breach of security, phishing incident, ransomware or malware attack or other incident in which any Personal Information or other Data or information included in the Transferred Data was lost, stolen, accessed, used, disclosed, modified or exfiltrated in an unauthorized or unlawful manner, or has received any written notices or complaints from any Person has gained or been the subject of any claim, proceeding or investigation with respect thereto or (B) been required under any Information Privacy and Security Requirements to notify any Person of the loss or theft of or unauthorized or unlawful access to any Personal Information or other Data or information included in the Transferred Data, that would prevent the transfer of the Transferred Data to Celsius in accordance with the Transaction Documents or that would be reasonably expected to cause any exposure or leakage of or unauthorized access to the IT Assets owned bymaterial Trade Secrets included in the Transferred Data. PepsiCo and its Affiliates have, in each case to the extent required by Information Privacy and Security Requirements, provided notices, obtained consents, and satisfied all other requirements necessary for their processing of Personal Information included in the Transferred Data in connection with the Acquired Business and for the consummation of the Transactions that can be satisfied by PepsiCo and its Affiliates, including providing notices and obtaining consents necessary for the lawful and effective transfer of the Transferred Data to Celsius. Except as would not reasonably be expected, individually or in the aggregate, to be material to the Acquired Business, PepsiCo and its Affiliates have contractually obligated any third parties that process, access or store Personal Information or other Data or information included in the Transferred Data to abide by terms that are compliant in all material respects with applicable Information Privacy and Security Requirements. Neither the execution, delivery or performance of this Agreement or the Additional Agreements nor the consummation of the Transactions will result in a breach or violation of, or used constitute a default under, any Information Privacy and controlled bySecurity Requirements. Neither PepsiCo nor any of its Affiliates is subject to any Information Privacy and Security Requirements that, Tempranillo following the Closing, would prevent Celsius from receiving or using any Personal Information or other Data or information included in the Transferred Data in all material respects in the manner in which PepsiCo and its SubsidiariesAffiliates receive and use any Personal Information or other Data or information included in the Transferred Data in the operation of the Acquired Business prior to the Closing.
(db) To the Knowledge of Tempranillo, Tempranillo PepsiCo and its Subsidiaries Affiliates have executed current at all times taken commercially reasonable actions and valid Business Associate Agreements with each (i) customer thatmeasures, including adopting and following policies and procedures and putting in place technological, physical, administrative, operational and other safeguards, to protect the Knowledge confidentiality, integrity, availability, privacy and security of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations)Transferred Data. Tempranillo PepsiCo and its Subsidiaries are in Affiliates have timely remediated and addressed any material compliance with such Business Associate Agreements and, and adverse audit findings relating to the Knowledge implementation of Tempranillotechnical, physical, administrative and operational security measures pertinent to safeguarding material Trade Secrets included in the Transferred Data. There have been no covered entity material failures, breakdowns or subcontractor has materially breached performance reductions of any such Business Associate Agreement with Tempranillo Information Systems reasonably expected to cause any exposure or any leakage of its Subsidiariesor unauthorized access to the material Trade Secrets included in the Transferred Data.
(ec) To The Information Systems and related services provided under the extent Tempranillo or any Transition Services Agreement will be sufficient for the operation of its Subsidiaries has de-identified user data, Tempranillo the Acquired Business immediately after the Closing in all material respects in the same manner as currently conducted by PepsiCo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified dataAffiliates.
Appears in 1 contract
Data Privacy and Security. (a) Since Except for those matters that, individually or in the aggregate, have not been and would not reasonably be expected to be material to the North American Business or the Transferred Group Members, taken as a whole, Parent and the Parent Subsidiaries are and at all times since January 1, 2018, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo and its Subsidiaries of any Personal Data are and 2018 have been in compliance in all material respects with (i) all Privacy Laws and (ii) all Privacy and Data Security Policies and written contractual requirements pertaining to the processing of Personally Identifiable Information (collectively, the “Parent Privacy RequirementsCommitments”).
(b) Parent and the Parent Subsidiaries have, except where with respect to the North American Business, (i) implemented and maintained industry standard security measures, plans, procedures, controls, and programs, including a written information security program and a data protection management system to prevent data breaches, and (ii) established and implemented Privacy and Data Security Policies and other organizational, physical, administrative and technical measures regarding privacy, cyber security and data security.
(c) The execution, delivery and performance of this Agreement will not cause a material breach of any instances Privacy Laws applicable to the North American Business or Parent Privacy Commitments, in each case with respect to the North American Business only. Copies of non-compliance all current Privacy and Data Security Policies applicable to the North American Business have been made available to Purchaser and such copies are true and complete.
(d) Except for those matters that, individually or in the aggregate, have not had, been and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect be material to the physical and electronic security and privacy of Personal Data that are designed North American Business or the Transferred Group Members, taken as a whole, to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As Knowledge of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s KnowledgeParent, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries.
(d) To the Knowledge of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer thatneither Parent nor the Parent Subsidiaries have suffered any accidental or unlawful destruction, loss, alteration or unauthorized disclosure or access to or misuse of any Personally Identifiable Information, including Personally Identifiable Information processed by a third party on Parent’s or the Parent Subsidiaries’ behalf and (ii) no Action by any Governmental Entity or Person has been asserted or, to the Knowledge of TempranilloParent, is threatened against Parent or the Parent Subsidiaries alleging a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements andviolation of any Person’s privacy or Personally Identifiable Information or data rights, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its SubsidiariesParent Privacy Commitments.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Data Privacy and Security. (a) Since There is not currently pending or, to Acquirer’s knowledge, threatened, and there has not since January 1, 20182020 been any, Proceeding against any Acquirer Group Member initiated by (i) the collectionUnited States Federal Trade Commission, acquisitionany state attorney general or similar state official; (ii) any other Governmental Entity, useforeign or domestic; (iii) any regulatory entity, storageprivacy regulator or otherwise, transfer or (including iv) any crossother Person, in each case, with respect to privacy, cybersecurity, and, to Acquirer’s knowledge, there are no facts upon which such a Proceeding could be based.
(b) Except as set forth on Section 5.13 of the Acquirer’s Disclosure Schedules, there have not been any actual, suspected, or alleged material Security Incidents or actual or alleged claims related to material Security Incidents, and, to Acquirer’s knowledge, there are no facts or circumstances which could reasonably serve as the basis for any such allegations or claims. There are no data security, information security, or other technological vulnerabilities with respect to the Acquirer Group’s services or with respect to the Acquirer IT Systems that would have a materially adverse impact on their operations or cause a material Security Incident.
(c) The Acquirer Group Members own or have license to use pursuant to an Acquirer Material Contract the Acquirer IT Systems as necessary to operate their respective businesses as currently conducted and such Acquirer IT Systems are sufficient for the operation of their respective businesses as currently conducted. The Acquirer Group Members have back-border transfers)up and disaster recovery arrangements, distribution or dissemination by Tempranillo procedures and facilities for the continued operation of its Subsidiaries businesses in the event of any Personal Data are a failure of the Acquirer IT Systems that are, in the reasonable determination of Acquirer, commercially reasonable and have been in compliance accordance in all material respects with the Privacy Requirements, except where any instances of non-compliance have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effectstandard industry practice. Since January 1, 20182020, there have has not been no any material breaches disruption, failure or, to Acquirer’s knowledge, unauthorized access with respect to any of the Acquirer IT Systems that has not been remedied, replaced or mitigated in all material violations respects. To Acquirer’s knowledge, none of the Acquirer IT Systems contain any such security measuresworm, bomb, backdoor, trap doors, Trojan horse, spyware, keylogger software, clock, timer or other damaging devices, malicious codes, designs, hardware component, or software routines that causes the Acquirer Software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiariesperson.
(d) To the Knowledge of TempranilloThe Acquirer Group Members have, Tempranillo and its Subsidiaries since January 1, 2020 have executed current had, in place reasonable and valid Business Associate Agreements with each appropriate administrative, technical, physical and organizational measures and safeguards to (i) customer thatensure the integrity, to the Knowledge of Tempranillosecurity, is a “covered entity” (as defined by HIPAA and the corresponding regulations) continued, uninterrupted, and error-free operation of the Acquirer IT Systems, and the confidentiality of the source code of any Acquirer Software, and (ii) “subcontractor” (as defined by HIPAA to protect Business Data against loss, damage, and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements andunauthorized access, to the Knowledge of Tempranillouse, no covered entity modification, or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiariesother misuse.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Data Privacy and Security. (a) Since January 1Except as would not, 2018individually or in the aggregate, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo and its Subsidiaries of any Personal Data are and have been in compliance in all material respects with the Privacy Requirements, except where any instances of non-compliance have not had, and would not reasonably be expected to have, have a Tempranillo Paramount Material Adverse Effect, since January 1, 2021: (a) Paramount and its Subsidiaries and, to the knowledge of Paramount, all vendors, processors or other third parties Processing Personal Information for or on behalf of Paramount or any Subsidiaries of Paramount or otherwise sharing Personal Information with Paramount or any Subsidiaries of Paramount (each a “Paramount Data Partner”) have complied with (i) all applicable Privacy Laws and (ii) all published privacy and data security policies, notices and statements to which Paramount and its Subsidiaries are subject.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policiesExcept as would not, proceduresindividually or in the aggregate, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, have a Tempranillo Paramount Material Adverse Effect. Since , since January 1, 20182021, there Paramount and its Subsidiaries have, and have been no material breaches required any Paramount Data Partner to have, adopted and implemented at least commercially reasonable industry standard physical, technical, organizational, and administrative security measures and policies to (i) protect all Personal Information stored or material violations processed by or on behalf of Paramount and its Subsidiaries against any such accidental, unlawful or unauthorized access, use, loss, disclosure, alteration, destruction, compromise or other Processing (a “Security Incident”) and (ii) identify and address internal and external risks to the privacy and security measures, of Personal Information processed by or any unauthorized access on behalf of any Personal Data or Tempranillo’s or Paramount and its Subsidiaries’ business data by any Third Party. As of Except as would not, individually or in the date of this Agreementaggregate, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, have a Tempranillo Paramount Material Adverse Effect, since January 1, 2021, Paramount, Subsidiaries of Paramount (and, to the knowledge of Paramount, Paramount Data Partners with respect to Personal Information of Paramount and its Subsidiaries) have not experienced a Security Incident.
(c) Except as would not not, individually or in the aggregate, reasonably be expected to have a Tempranillo Paramount Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 20182021, no Person has gained unauthorized access in relation to the IT Assets owned byany Security Incident, or used and controlled by, Tempranillo and its Subsidiaries.
(d) To the Knowledge none of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer that, to the Knowledge of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo Paramount or any of its Subsidiariesthe Subsidiaries of Paramount has been the subject of any formal complaint, claim or investigation or been required to notify any Person.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Data Privacy and Security. (a) Since January 1, 2018, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo TPCO and each of its Subsidiaries of any Personal Data are complies, and have been in compliance has complied in all material respects respects, with the all Privacy and Information Security Requirements, except where . Neither TPCO nor any instances of non-compliance have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policieshave been notified in writing of, proceduresor is the subject of, trainingsany complaint, regulatory investigation or proceeding related to Processing of Personal Data by any Governmental Entity or payment card association, regarding any violations of any Privacy and security measures Information Security Requirement by or with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries.
(d) To the Knowledge of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer that, to the Knowledge of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo TPCO or any of its Subsidiaries.
(eb) To TPCO and each of its Subsidiaries employs commercially reasonable organizational, administrative, physical and technical safeguards that comply with all Privacy and Information Security Requirements to protect Personal Data within its custody or control and requires the extent Tempranillo same of all vendors under contract with TPCO that Process Personal Data on its behalf. TPCO and each of its Subsidiaries have provided all requisite notices and obtained all required consents or otherwise identified legal basis for Personal Data, and satisfied all other requirements (including but not limited to notification to Governmental Entities), necessary for the Processing (including international and onward transfer) of all Personal Data in connection with the conduct of the TPCO Business as currently conducted and in connection with the consummation of the transactions contemplated hereunder, except in each case, as would not be reasonably expected to have a Material Adverse Effect with respect to TPCO.
(c) Neither TPCO nor any of its Subsidiaries, to TPCO's knowledge, has suffered a security breach with respect to any of the Personal Data and, to TPCO's knowledge, there has been no unauthorized or illegal use of or access to any Personal Data. Neither TPCO nor any of its Subsidiaries has de-identified user datanotified, Tempranillo or been required to notify, any Person of any information security breach involving Personal Data. To TPCO's knowledge, TPCO Systems have had no material errors or defects, and/or if TPCO Systems have had any material errors or defects, such have been fully remedied and its Subsidiaries have obtained all rights necessary contain no code designed to undertake de-identification disrupt, disable, harm, distort, or otherwise impede in any manner the legitimate operation of such user data and has de-identified such user data in accordance with the requirements TPCO Systems (including what are sometimes referred to as "viruses," "worms," "time bombs," or "back doors" or any other form of HIPAA and other Privacy Requirementsmalware) that have not been removed or fully remedied. To TPCO's knowledge, neither it nor any of its Subsidiaries, have experienced any material disruption to, or material interruption in, the extent Tempranillo conduct of its business that effected the business for more than one calendar week, and its Subsidiaries have used de-identified dataattributable to a defect, Tempranillo and its Subsidiaries have obtained all rights necessary for bug, breakdown, ransomware event, unauthorized access, introduction of a virus or other malicious programming, or other failure or deficiency on the use part of such de-identified dataany computer Software or the TPCO Systems.
Appears in 1 contract
Sources: Business Combination Agreement (TPCO Holding Corp.)
Data Privacy and Security. (a) Since 4.12.1 Each Seller is in material compliance, and since January 1, 20182022, the collectionhas at all times been in material compliance, acquisitionwith all applicable Privacy and Data Security Requirements. Sellers have at all times obtained all rights, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo consents and its Subsidiaries of any licenses necessary to Process Personal Data are in the manner it has been Processed, is now Processed and as proposed to be Processed in the Business by any Person on their behalf.
4.12.2 Sellers have been in compliance in at all material respects with the Privacy Requirements, except where any instances of non-compliance have not hadtimes maintained, and would not reasonably be expected to havepresently maintain, a Tempranillo Material Adverse Effect.
(b) Tempranillo reasonable backup, security and its Subsidiaries maintain disaster recovery plans, in each case, using commercially reasonable policies, procedures, trainings, efforts no less than industry-standard and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies applicable Privacy and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse EffectData Security Requirements for the Business-Utilized IT Systems. Since January 1, 20182022, to Sellers’ Knowledge, there have been (i) no material breaches unauthorized access to or material violations unauthorized use of any such Business-Utilized IT Systems and (ii) no unauthorized intrusions or breaches of security measureswith respect to any Business-Utilized IT Systems.
4.12.3 Neither Seller has received any subpoenas, demands, or other written notices from any Governmental Body investigating, inquiring into, or otherwise relating to any actual or potential violation of any Privacy and Data Security Requirements, and neither Seller is under investigation by any Governmental Body for any actual or potential violation of any Privacy and Data Security Requirements. No Person (including any Governmental Body) has commenced any Action nor has any written notice or enforcement Action of any kind been served on, or initiated against, either Seller under any applicable Privacy and Data Security Requirements or with respect to loss, damage or unauthorized access access, use or modification of any Personal Data by or Tempranillo’s on behalf of either Seller and, to Sellers’ Knowledge, there are no facts or its Subsidiariescircumstances that could form the basis for any such claim. Since January 1, 2022, there have been no, and there are currently no pending or, to Sellers’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to fines or other penalties facing either Seller in connection with any such obligation, policy, Applicable Law in relation to disclosure of Personal Data with respect to the operation of the Business or a violation of any breach applicable Privacy and Data Security Requirements.
4.12.4 To the extent Sellers use Personal Data as part of developing, training, operating or alleged breach thereof, except as has not had, and would not reasonably be expected to havemaintaining internal or third-party Artificial Intelligence Tools, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as record is maintained of the date of this Agreement, the IT Assets owned by, or what data is being used and controlled byhas been used for these purposes. Sellers use and have used commercially reasonable efforts (including, Tempranillo and its Subsidiaries at a minimum, by conducting regular audits) to ensure (i) operate Sellers have sufficient rights in all data Processed by Sellers’ Artificial Intelligence Tools and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1Sellers’ Artificial Intelligence Tools operate as intended, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) in compliance with all applicable Laws and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected likely to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledgeharm or disparage Sellers or the reputation or goodwill of Sellers. Sellers’ use of Artificial Intelligence Tools does not and, since January 1, 20182022, no Person has gained not, resulted in the unauthorized disclosure to, or access by, any third party of Personal Data in possession of Sellers.
4.12.5 The consummation of the transactions contemplated by this Agreement as well as any subsequent use of Personal Data in a substantially similar manner to how such Personal Data is used by Sellers in connection with the Business immediately prior to the IT Assets owned by, Closing will not breach or used otherwise cause any violation of any Privacy and controlled by, Tempranillo and its SubsidiariesData Security Requirements.
(d) To the Knowledge of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer that, to the Knowledge of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiaries.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Data Privacy and Security. (a) Since There is not currently pending or, to Acquiror’s knowledge, threatened, and there has not since January 1, 20182019 been any, Proceeding against any Acquiror Group Member initiated by (i) the collectionUnited States Federal Trade Commission, acquisitionany state attorney general or similar state official; (ii) any other Governmental Entity, useforeign or domestic; (iii) any regulatory entity, storageprivacy regulator or otherwise, transfer or (including iv) any crossother Person, in each case, with respect to privacy, cybersecurity, and, to Acquiror’s knowledge, there are no facts upon which such a Proceeding could be based.
(b) Except as set forth on Section 5.13 of the Acquiror’s Disclousre Schedules, there have not been any actual, suspected, or alleged material Security Incidents or actual or alleged claims related to material Security Incidents, and, to Acquiror’s knowledge, there are no facts or circumstances which could reasonably serve as the basis for any such allegations or claims. There are no data security, information security, or other technological vulnerabilities with respect to the Acquiror Group’s services or with respect to the Acquiror IT Systems that would have a materially adverse impact on their operations or cause a material Security Incident.
(c) The Acquiror Group Members own or have license to use pursuant to an Acquiror Material Contract the Acquiror IT Systems as necessary to operate their respective businesses as currently conducted and such Acquiror IT Systems are sufficient for the operation of their respective businesses as currently conducted. The Acquiror Group Members have back-border transfers)up and disaster recovery arrangements, distribution or dissemination by Tempranillo procedures and facilities for the continued operation of its Subsidiaries businesses in the event of any Personal Data are a failure of the Acquiror IT Systems that are, in the reasonable determination of Acquiror, commercially reasonable and have been in compliance accordance in all material respects with the Privacy Requirements, except where any instances of non-compliance have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effectstandard industry practice. Since January 1, 20182019, there have has not been no any material breaches disruption, failure or, to Acquiror’s knowledge, unauthorized access with respect to any of the Acquiror IT Systems that has not been remedied, replaced or mitigated in all material violations respects. To Acquiror’s knowledge, none of the Acquiror IT Systems contain any such security measuresworm, bomb, backdoor, trap doors, Trojan horse, spyware, keylogger software, clock, timer or other damaging devices, malicious codes, designs, hardware component, or software routines that causes the Acquiror Software or any portion thereof to be erased, inoperable or otherwise incapable of being used, either automatically, with the passage of time or upon command by any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Software. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiariesperson.
(d) To the Knowledge of TempranilloThe Acquiror Group Members have, Tempranillo and its Subsidiaries since January 1, 2019 have executed current had, in place reasonable and valid Business Associate Agreements with each appropriate administrative, technical, physical and organizational measures and safeguards to (i) customer thatensure the integrity, to the Knowledge of Tempranillosecurity, is a “covered entity” (as defined by HIPAA and the corresponding regulations) continued, uninterrupted, and error-free operation of the Acquiror IT Systems, and the confidentiality of the source code of any Acquiror Software, and (ii) “subcontractor” (as defined by HIPAA to protect Business Data against loss, damage, and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements andunauthorized access, to the Knowledge of Tempranillouse, no covered entity modification, or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiariesother misuse.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Sources: Merger Agreement (Akerna Corp.)
Data Privacy and Security. (a) Since Except as would not have a Company Material Adverse Effect, each member of the Company Group is, and at all times since January 1, 20182021 has been, in compliance with all applicable privacy and information security obligations to which it is subject, including with respect to the Company Group’s collection, acquisitionmaintenance, transmission, accessing, transfer, storage, use, storagedisclosure, transfer disposal, and other processing (including any cross-border transferscollectively, “Processing”) of Personal Information, under applicable Privacy Laws (including, as applicable, Health Insurance Portability and Accountability Act, as amended by the Health Information Technology for Economic and Clinical Health Act (“HIPAA”)), distribution Contracts, industry standards (including, as applicable, the Payment Card Industry Data Security Standard), privacy policies or dissemination by Tempranillo and its Subsidiaries online terms of any Personal use (collectively, “Data are and have been in compliance in all material respects with the Privacy Protection Requirements, except where any instances of non-compliance have not had, and ”). Except as would not reasonably be expected to have, have a Tempranillo Company Material Adverse Effect, neither the Company nor any Company Subsidiary has received any written or, to the Knowledge of the Company, other notices or complaints from any person or Governmental Authority alleging, or been subject to any audits or investigations concerning, any failure to comply with any Data Protection Requirements. Except as would not have a Company Material Adverse Effect, there has been no unauthorized access to, or use or disclosure of, any Personal Information collected, maintained, processed or stored by the Company or any Company Subsidiary. Except as would not have a Company Material Adverse Effect, the Company and the Company Subsidiaries have not, nor to the Knowledge of the Company has any third party Processing Business Data, notified or been required under Data Protection Requirements to notify any Governmental Authority or any other person of a data security breach, Security Incident or violation of any data security policy or Data Protection Requirement pertaining to the business of the Company or any Company Subsidiary.
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or Tempranillo’s or its Subsidiaries’ business data by any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Company Material Adverse Effect, to Tempranillo’s Knowledgethe Systems are adequate for, as of the date of this Agreement, the IT Assets owned by, or used reasonably maintained and controlled by, Tempranillo in sufficiently good working condition and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with performance for the conduct of their respective businesses, (ii) since January 1, 2018, have not malfunctioned or failed (except for malfunctions or failures that have been fully remedied) the business of the Company and (iii) are free from bugs each Company Subsidiary as currently conducted and other defects and do not contain any “virus”, “worm”, “spyware” or other malicious Softwareas currently contemplated to be conducted. Except as would not reasonably be expected to have a Tempranillo Company Material Adverse Effect, the Company and each Company Subsidiary has implemented and maintained all necessary and appropriate controls, policies, procedures, and safeguards to Tempranillo’s Knowledgemaintain and protect the confidentiality, since January 1integrity and security of the Systems, 2018Personal Information and other Business Data used in connection with their businesses, and there has been no Person has gained failure, malfunction, breakdown, performance reduction or other adverse event affecting any Systems, nor any unauthorized access to, or use, intrusion, or breach of security of, any Systems, or any other loss, or unauthorized Processing of any Business Data, including Personal Information, in the possession or control of the Company or any Company Subsidiary (each, as “Security Incident”), nor any incidents under internal review or investigations relating to the IT Assets owned bysame. Except as would not have a Company Material Adverse Effect, the Company and each Company Subsidiary maintains commercially reasonable backup and data recovery, disaster recovery, and business continuity plans, procedures, and facilities, and is and has been in compliance with all of the Company Group’s policies related to the foregoing. Except as would not have a Company Material Adverse Effect, the Systems are free from any disabling codes or instructions, spyware, Trojan horses, worms, viruses or other Software routines that could permit or cause unauthorized access to, or used and controlled bydisruption, Tempranillo and its Subsidiariesimpairment, disablement, or destruction of, Software, data or other materials.
(d) To the Knowledge of Tempranillo, Tempranillo and its Subsidiaries have executed current and valid Business Associate Agreements with each (i) customer that, to the Knowledge of Tempranillo, is a “covered entity” (as defined by HIPAA and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo and its Subsidiaries are in material compliance with such Business Associate Agreements and, to the Knowledge of Tempranillo, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiaries.
(e) To the extent Tempranillo or any of its Subsidiaries has de-identified user data, Tempranillo and its Subsidiaries have obtained all rights necessary to undertake de-identification of such user data and has de-identified such user data in accordance with the requirements of HIPAA and other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified data.
Appears in 1 contract
Data Privacy and Security. (a) Since January 1, 2018, the collection, acquisition, use, storage, transfer (including any cross-border transfers), distribution or dissemination by Tempranillo A2iA and its Subsidiaries of any Personal Data are comply, and at all times during the past three (3) years have been in compliance complied, in all material respects with its internal privacy policies relating to the Privacy Requirementsuse, except where collection, storage, disclosure and transfer of any instances Personal Information collected by A2iA or its Subsidiaries or by third parties acting on behalf of non-compliance have not had, and would not reasonably be expected or having authorized access to have, a Tempranillo Material Adverse Effect.the records of A2iA or its Subsidiaries. Neither A2iA nor any of its Subsidiaries has received any written complaint
(b) Tempranillo and its Subsidiaries maintain commercially reasonable policies, procedures, trainings, and security measures with respect to the physical and electronic security and privacy of Personal Data that are designed to achieve compliance with the Privacy Requirements, and Tempranillo and its Subsidiaries are in compliance with such policies and procedures, except as have not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect. Since January 1, 2018, there have been no material breaches or material violations of any such security measures, or any unauthorized access of any Personal Data or TempranilloA2iA’s or its Subsidiaries’ business data by operation of any Third Party. As of the date of this Agreement, no written claim or other Proceeding is pending against Tempranillo or any of its Subsidiaries, nor to Tempranillo’s Knowledge, threatened, relating to any such obligation, policy, Applicable Law in relation to Personal Data or any breach or alleged breach thereof, except as has not had, and would not reasonably be expected to have, a Tempranillo Material Adverse Effect.
(c) Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, as of the date of this Agreement, the IT Assets owned by, or websites used and controlled by, Tempranillo and its Subsidiaries (i) operate and perform as required by Tempranillo and its Subsidiaries in connection with the conduct business of their respective businessesA2iA and its Subsidiaries, (ii) since January 1the content thereof, 2018and all data processed, have not malfunctioned collected, stored or failed (except for malfunctions or failures that have been fully remedied) and (iii) are free from bugs and other defects disseminated in connection therewith, comply in all material respects with all Applicable Laws, and do not contain violate any “virus”, “worm”, “spyware” Person’s right of privacy or other malicious Softwarepublicity. Except as would not reasonably be expected to have a Tempranillo Material Adverse Effect, to Tempranillo’s Knowledge, since January 1, 2018, no Person has gained unauthorized access to the IT Assets owned by, or used and controlled by, Tempranillo and its Subsidiaries.
(d) To the Knowledge of Tempranillo, Tempranillo A2iA and its Subsidiaries have executed current posted privacy policies governing A2iA’s and valid Business Associate Agreements with each (i) customer thatits Subsidiaries’ use of data, to the Knowledge and disclaimers of Tempranilloliability, is a “covered entity” (as defined by HIPAA on its websites, and the corresponding regulations) and (ii) “subcontractor” (as defined by HIPAA and the corresponding regulations). Tempranillo A2iA and its Subsidiaries are in material compliance have complied with such Business Associate Agreements and, applicable privacy policies in all material respects. A2iA and its Subsidiaries have taken reasonable steps in accordance with normal industry practices to secure its websites and data from unauthorized access or use thereof by any Person. To the Knowledge of TempranilloSellers’ Knowledge, no covered entity or subcontractor has materially breached any such Business Associate Agreement with Tempranillo or any of its Subsidiaries.
(e) To the extent Tempranillo website security measure implemented by A2iA or any of its Subsidiaries has de-identified user databeen penetrated, Tempranillo and no website maintained by A2iA or any of its Subsidiaries have obtained all rights necessary to undertake dehas been the target of any defacement, unauthorized access, denial-identification of such user data and has deof-identified such user data in accordance with the requirements of HIPAA and service assault or other Privacy Requirements. To the extent Tempranillo and its Subsidiaries have used de-identified data, Tempranillo and its Subsidiaries have obtained all rights necessary for the use of such de-identified dataattack by hackers.
Appears in 1 contract
Sources: Share Purchase Agreement