Privacy and Data Security. (a) The Company is in compliance with all Data Security Requirements in all material respects. Neither: (i) the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security Requirement. (b) The Company has not received any subpoena, demand, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standards. (c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects. (d) Except as disclosed in Schedule D.45 of the Company Disclosure Letter, to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Information.
Appears in 1 contract
Privacy and Data Security. (ai) The Collection and Use and dissemination by each member of the Company Group of any Personal Data within such member of Company Group’s custody or control is in compliance in all material respects with all applicable Information Privacy and Security Laws and all Personal Data Obligations. Each member of the Company Group has consistently posted a privacy policy in a clear and conspicuous location on all websites and any mobile applications owned or operated by such member of the Company Group.
(ii) Each member of the Company Group maintains policies and procedures regarding data security and privacy and maintains administrative, technical and physical safeguards that are commercially reasonable and, in any event, in compliance with all Data applicable Information and Privacy and Security Requirements Laws and all Contracts to which such member of the Company Group is bound. Each member of the Company Group has complied at all times since the Reference Date in all material respects. Neither: (i) respects with the execution, delivery or performance terms of this Agreement nor (ii) the consummation all Contracts to which such member of the Arrangement Company Group is bound relating to data privacy, security or any breach notification (including provisions that impose conditions or restrictions on the collection, use, disclosure, transmission, destruction, maintenance, storage, or safeguarding of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementPersonal Data).
(biii) The Company has not received At any subpoenatime since the Reference Date, demandto the Knowledge of the Company, inquirythere have been no security breaches relating to, or violations of any Information Privacy and Security Law regarding, or any unauthorized access, disclosure, or use of, any Personal Data within a member of Company Group’s custody or control. No notice has been provided to any member of the Company Group by a third party vendor or any other written person of any security breach relating to Personal Data that such Person maintains for or on behalf of the Company Group. To the Knowledge of the Company, no member of the Company Group has experienced a loss or unauthorized disclosure, use, or breach of privacy or security of any Personal Data in the custody or control of such member of the Company Group that would have required notice from to any third Person (including any Governmental Authority investigating, inquiring into, Entity or otherwise parties to any Contract) under any applicable Information Privacy and Security Law. No Person (including any Governmental Authority) has commenced any Action relating to any actual or potential violation member of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by Group’s information privacy or data security practices, or to the Knowledge of the Company, threatened any Governmental Authority for such Action or made any actual complaint, investigation, or potential violation of any Data Security Requirement or inquiry relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardssuch practices.
(civ) The Each member of the Company Group has taken commercially reasonable steps consistent with to limit access to Personal Data Security Requirements to protect the integrity and security within such member of its information technology systems and to ensure that Personal Information in its possession, Company Group’s custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice andto: (ix) includes administrativethose Company Group personnel and third-party vendors providing services to or on behalf of the Company Group who have a need to know such Personal Data in the execution of their duties to the applicable member of the Company Group; and (y) such other Persons permitted to access such Personal Data in accordance with the privacy policies and terms of use, technical all applicable Information Privacy and physical safeguards, controls Security Laws and all Contracts to which such member of the Company Group is bound.
(v) Each member of the Company Group has implemented security measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed prevent unauthorized access to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threatsinformation technology networks. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 All of the Company Disclosure LetterGroup’s security measures are designed to be consistent with the requirements of applicable Laws and are designed to (x) prevent the unauthorized disclosure of confidential information (including Personal Data) of the applicable member of the Company Group, (y) prevent unauthorized access (and immediately terminate such unauthorized access) to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possession, custody or control networks and information system of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any applicable member of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, Company Group and there has been no unauthorized or illegal use (z) facilitate the applicable member of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service Group’s identification of the person accessing or other attack designed attempting to materially interrupt operations or to interrupt access to the Company’s computer systems; networks and (iv) information system of the applicable member of the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal InformationGroup.
Appears in 1 contract
Sources: Merger Agreement (Invitae Corp)
Privacy and Data Security. (ai) The Collection and Use and dissemination by the Company of any Personal Data is in compliance with all Data Security Requirements in all material respectsrespects with the Company’s privacy policies and terms of use, industry standards, all applicable Information Privacy and Security Laws, all Personal Data Obligations, and all Contracts to which the Company is bound. Neither: (i) the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any No Personal Data Security Requirement.
(b) The Company has not received any subpoena, demand, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, is stored or otherwise relating to any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is maintained outside the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standards.
(c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed United States by the Company or any third party. The Company has not engaged in cross-border processing of Personal Data. True and complete copies of all privacy policies that have been used by the Company since the Reference Date have been provided to Buyer. The Company has consistently posted a privacy policy in a clear and conspicuous location on all websites and any mobile applications owned or operated by the Company.
(ii) The Company does not Collect or Use Personal Data from any Person in any manner other than as described in the Contracts and privacy policies delivered to Buyer.
(iii) The Company maintains policies and procedures regarding data security and privacy and maintains administrative, technical and physical safeguards that are commercially reasonable and, in any event, in compliance with industry standards, all applicable Information and Privacy and Security Laws and all Contracts to which the Company is bound. True and complete copies of all such policies and procedures have been provided to Buyer. The Company has complied at all times in all respects with the terms of all Contracts to which the Company is a party operating at relating to data privacy, security or breach notification (including provisions that impose conditions or restrictions on the direction collection, use, disclosure, transmission, destruction, maintenance, storage, or safeguarding of Personal Data).
(iv) At any time since the Reference Date, there have been no security breaches relating to, or violations of any security policy or Information Privacy and Security Law regarding, or any unauthorized access, disclosure, or use of, any data or information used by the Company, including Personal Data. No notice has been provided to the Company by a third party vendor or any other person of any security breach relating to Personal Data. The Company has not experienced a loss or unauthorized disclosure, use, or breach of privacy or security of any Personal Data in the custody or control of the Company that would have required notice to any third Person (including any Governmental Entity or parties to any Contract) under any applicable Law. No Person (including any Governmental Authority) has commenced any Action relating to the Company’s information privacy or data security practices, or to the Knowledge of the Company, threatened any such Action or made any complaint, investigation, or inquiry relating to such practices.
(v) The Company does not (x) have or solicit any customers in the European Economic Area, or (y) except as set forth in Section 4.15(g)(v) of the Disclosure Schedule, process, transmit, or store any Personal Data of any Persons located in the European Economic Area.
(vi) The Company has taken all required steps to limit access to Personal Data to: (x) those Company personnel and third-party vendors providing services to or on behalf of the Company who have a need to know such Personal Data in the execution of their duties to the Company; and (y) such other Persons permitted to access such Personal Data in accordance with the privacy policies and terms of use, industry standards, all applicable Information Privacy and Security Laws and all Contracts to which the Company is bound.
(vii) The Company maintains a written technical information security program that contains administrative, technical and physical safeguards (including encryption) compliant in all respects with industry standards and applicable Information Privacy and Security Laws (the “Security Program”). The Security Program is designed to: (v) protect the integrity and confidentiality of Personal Data; (w) protect against reasonably anticipated threats or hazards to the security of Personal Data; (x) protect against the unauthorized access, disclosure or use of Personal Data; (y) address computer and network security; and (z) provide for the secure destruction and disposal of Personal Data. The Security Program has been updated as required by all applicable Information Privacy and Security Laws. All third-party vendors or persons with access to Personal Data have entered into contracts or written agreements with the Company requiring that such vendors or persons maintain a substantially similar security program.
(viii) The Company controls the access to its computer and information technology networks through the utilization of industry-standard or better security measures that are designed to prevent unauthorized access to such networks. All of the Company’s security measures are designed to be consistent with or exceed industry standards and the requirements of applicable Laws and are designed to (x) prevent the unauthorized disclosure of confidential information (including Personal Data) of the Company, (iiy) includes disaster recovery, business continuity, incident response, prevent access without express authorization (and security plans, procedures immediately terminate such unauthorized access) to the networks and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 information system of the Company Disclosure Letter, to the knowledge of Company and (iz) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of facilitate the Company’s computer systems identification of the person making or Information Security Program has occurred or is threatened in writing, and there has been no attempting to make such unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationaccess.
Appears in 1 contract
Privacy and Data Security. (a) The Company is in compliance with all Data Security Requirements complies in all material respectsrespects with Applicable Privacy and Security Laws, and with such privacy and information security obligations to which it is subject under contract, privacy policy, or online terms of use. Neither: The Company maintains policies and procedures that comply in all material respects with (i) the execution, delivery or performance of this Agreement nor Applicable Privacy and Security Laws and (ii) privacy and information security obligations to its customers, data subjects, or others, under contract, privacy policy, or online terms of use. The Company has obtained all required consents to its collection, use, retention and disclosure of Personal Information in accordance with Applicable Privacy and Security Laws. The Company has, to the consummation extent required by Applicable Privacy and Security Laws, obtained valid consents from individuals to whom it sends direct marketing communications or has the necessary implied consents for the individuals to whom it sends direct marketing communications. To the Knowledge of the Arrangement Company, the Company has not disclosed or transferred any Personal Information outside the European Economic Area without a valid legal basis for such transfer under Chapter V of the GDPR. The Company has not, nor, to the Knowledge of the Company have any of the transactions contemplated by this Agreement Processors suffered any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to any Personal Information that would, individually or in the Plan of Arrangement will aggregate, result in any violation a material liability to the Company, and the Company and, to the Knowledge of any Data Security Requirement.
(b) The the Company, the Processors have passed all regulatory audits, where relevant, to which they have been subject, and the Company has not received contractual data protection provisions and restrictions with its Processors with respect to any subpoenaPersonal Information transferred from the Company to its Processors, demandand, inquiryto the Knowledge of the Company, or other written its Processors employ appropriate safeguards and provide notice from any Governmental Authority investigating, inquiring into, or otherwise relating to the Company of any actual or potential violation suspected unauthorized access to, use or disclosure of any Data Security Requirement or any Data Security IncidentPersonal Information. Since January 1, nor is 2018, the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standards.
(c) The Company has taken commercially reasonable steps implemented and maintained backup and disaster recovery technology consistent with Data Security Requirements industry standards and practices and has policies and procedures in place designed to protect provide for the integrity and security of its information technology systems the Company IT Systems and to ensure that Personal Information in its possession(including technical, custody organizational and administrative security measures) and has materially complied with such policies and procedures. There are no and have never been any actual or control is protected threatened complaints, proceedings, investigations, audits or other Actions against Data Security Incidents. The the Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, heldbrought by any Governmental Authority, or processed by any Person in respect of the collection, use or disclosure of Personal Information by the Company or a violation of any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, Applicable Privacy and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security IncidentsLaws. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed set forth in Schedule D.45 Section 4.21 of the Company Disclosure LetterSchedule, to all Personal Information is stored in the knowledge United States. All privacy policies of the Company (i) there currently in effect have been no Data Security Incidents delivered or other adverse events or incidents related made available to Personal Information in the possession, custody or control Purchaser. The completion of the Company, including any system failures, breakdowns, or viruses; (ii) no Transactions will not result in a breach or violation of any of Applicable Privacy and Security Laws by the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Information.
Appears in 1 contract
Sources: Stock Purchase Agreement (Inpixon)
Privacy and Data Security. (a) The Company is has a privacy policy (a “Privacy Policy”) regarding the collection, use, storage, retention disclosure and disposal of personal information in compliance connection with all Data Security Requirements the operation of the Business. The Company’s privacy practices conform in all material respects, and at all times have conformed in all material respects, to the Company’s applicable Privacy Policy. Neither: (i) the execution, delivery or performance of this Agreement nor (ii) the consummation None of the Arrangement Company’s contractual or other legal commitments conflict with the applicable Privacy Policy or privacy practices in any material respect. True and complete copies of all of the transactions contemplated Privacy Policies that have been used by this Agreement or the Plan of Arrangement will result Company at any time in any violation of any Data Security Requirementthe thirty-six (36) months prior to the date hereof have been provided to the Buyer.
(b) The Company has not received any subpoenacomplied in all material respects at all times with all Applicable Laws regarding the collection, demanduse, inquirystorage, transfer, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation disposal of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardspersonal information.
(c) The Company has taken commercially reasonable steps consistent is in compliance in all material respects with Data Security Requirements the terms of all Contracts to protect which the integrity and security Company is a party relating to data privacy, security, or breach notification (including provisions that impose conditions or restrictions on the collection, use, storage, transfer, or disposal of its information technology systems personal information).
(d) In the thirty-six (36) months prior to the date hereof, and to ensure that Personal Information in Seller’s Knowledge, no Person (including any Governmental Entity) has commenced any Proceeding relating to the Business’s information privacy or data security practices, including with respect to the collection, use, transfer, storage, or disposal of personal information maintained by or on behalf of the Company, or, to Seller’s Knowledge, threatened any such Proceeding, or made any complaint, investigation, or inquiry relating to such practices.
(e) The execution, delivery, and performance of this Agreement and the consummation of the contemplated transactions, including any transfer of personal information resulting from such transactions, will not violate any Applicable Law, each Privacy Policy as it currently exists or as it existed at any time during which any personal information was collected or obtained by or on behalf of the Company or other privacy and data security requirements imposed on Company or any party acting on its possessionbehalf under any Contracts. Upon the Closing, custody or control is protected against Data Security Incidentsthe Company will continue to have the right to use such personal information on identical terms and conditions as the Business enjoyed immediately prior to the Closing. The Company has established and complied at all timesimplemented (i) policies, programs, and procedures that, if followed, ensure that the Company is in compliance, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirementsany Applicable Law, that is consistent with industry practice and: (i) includes including administrative, technical technical, and physical safeguards, controls and measures that are designed to protect the confidentiality, integrity, and security and integrity of datapersonal information in its possession, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, heldcustody, or processed by the Company control against unauthorized access, use, modification, disclosure, or any third party operating at the direction of the Company, other misuse and (ii) includes data backup, data storage, system redundancy, disaster recovery, business continuity, incident responseavoidance and recovery technology and procedures, and security business continuity plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(df) Except as disclosed in Schedule D.45 of In the Company Disclosure Letter, thirty-six (36) months prior to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possessiondate hereof, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by experienced any denial-of-service material loss, damage, or other attack designed to materially interrupt operations unauthorized access, disclosure, use, or to interrupt access to breach of security of any personal information in the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents possession, custody, or other adverse events control, or incidents related to Personal Informationotherwise held or processed on its behalf.
Appears in 1 contract
Sources: Membership Interest Purchase Agreement (Atmos Energy Corp)
Privacy and Data Security. (a) The Company Entities have a privacy policy regarding the collection, use and disclosure of personal information in connection with the operation of the Business for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of personal information, or otherwise held or processed on its behalf and each Company Entity is and has been in material compliance with such privacy policy. The Company Entities have posted a privacy policy in a clear and conspicuous location on all Data Security Requirements in all material respects. Neither: (i) public websites owned or operated by the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementCompany Entities.
(b) The Without limiting the generality of Section 4.09, each Company Entity has not received any subpoenain the past five (5) years complied in all material respects with all applicable Laws regarding the collection, demandretention, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation use and protection of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardspersonal information.
(c) The Each applicable Company has taken commercially reasonable steps consistent Entity and, to the Knowledge of the Company, each other party thereto is in material compliance with Data Security Requirements the terms of all Material Contracts relating to protect data privacy, security or breach notification (including provisions that impose conditions or restrictions on the integrity and security collection, use, disclosure, transmission, destruction, maintenance, storage or safeguarding of its information technology systems and to ensure that Personal Information in its possessionpersonal information), custody or control is protected against Data Security Incidents. The Company has established and complied at all timesif any.
(d) No Person (including any Governmental Authority) has, in all material respectsthe past five (5) years, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes commenced any Action against any Company Entity relating to any Company Entity’s information privacy or data security practices relating to the personal information of consumers, including with respect to the access, disclosure or use of personal information of consumers maintained by or on behalf of any Company Entity, or, (ii) to the Knowledge of the Company, threatened any such Action, or made any complaint or investigation relating to such practices.
(e) The execution, delivery and performance of this Agreement and the consummation of the contemplated transactions, including any transfer of personal information resulting from such transactions, will not violate the privacy policy of any Company Entity as it currently exists.
(f) The Company Entities have established and implemented policies, programs and procedures that are commercially reasonable, in material compliance with applicable industry practices and appropriate, including administrative, technical and physical safeguards, controls and measures that are designed safeguards to protect the security and confidentiality, integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plansof personal information for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, procedures retention, use and facilitiesprotection of personal information against unauthorized access, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basisuse, including engaging independent third parties to test its computer systems for vulnerabilitiesmodification, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respectsdisclosure or other misuse.
(dg) Except as disclosed in Schedule D.45 of the Company Disclosure Letter, to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information The Business has not in the possessionpast five (5) years experienced any loss, custody or control of the Company, including any system failures, breakdownsdamage, or viruses; (ii) no unauthorized access, disclosure, use or breach or violation of security of any personal information for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of the Company’s computer systems personal information or Information Security Program has occurred otherwise held or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationprocessed on its behalf.
Appears in 1 contract
Sources: Membership Interest Purchase Agreement (Starco Brands, Inc.)
Privacy and Data Security. In connection with its collection, storage, use and/or disclosure of any information that constitutes “personal information,” “personal data” or “personally identifiable information” as defined in applicable laws (acollectively “Personal Information”) by or on behalf of the Company, the Company is and has been in compliance with (i) all laws applicable to the Company and its business (including, without limitation, laws relating to privacy, data security, telephone and text message communications, and marketing by email or other channels, to the extent applicable to the Company and its business) in all relevant jurisdictions, (ii) the Company’s current privacy policies and public written statements regarding the Company’s privacy or data security practices, and (iii) the requirements of any contract by which the Company is bound. The Company maintains and has maintained reasonable physical, technical, and administrative security measures and policies designed to protect all Personal Information owned, stored, used, maintained or controlled by or on behalf of the Company from and against unlawful, accidental or unauthorized access, destruction, loss, use, modification and/or disclosure. To the extent the Company maintains or transmits protected health information, as defined under 45 C.F.R. § 160.103, the Company is in compliance with the applicable requirements of the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act, including all Data Security Requirements rules and regulations promulgated thereunder. The Company is and has been in compliance in all material respects. Neither: (i) respects with all laws applicable to the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security Requirement.
(b) The Company has not received any subpoena, demand, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise and its business relating to any actual or potential violation data loss, theft and breach of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incidentsecurity notification obligations. No notice, complaint, claim, enforcement action, or litigation of any kind There has been threatened in writingno occurrence of (x) unlawful, served onaccidental or unauthorized destruction, initiated loss, use, modification or otherwise asserted, against the Company relating disclosure of or access to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standards.
(c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlledstored, maintainedused, held, maintained or processed controlled by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 behalf of the Company Disclosure Lettersuch that Privacy Requirements require or required the Company to notify government authorities, to the knowledge of Company (i) there have been no Data Security Incidents affected individuals or other adverse events parties of such occurrence or incidents related (y) unauthorized access to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any disclosure of the Company’s computer systems confidential information or Information Security Program has occurred or is threatened trade secrets that reasonably would be expected to result in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationa Material Adverse Effect.
Appears in 1 contract
Sources: Series a 1 Preferred Stock Purchase Agreement (Miso Robotics, Inc.)
Privacy and Data Security. (a) The Company has a privacy policy regarding the collection, use and disclosure of personal information in connection with the operation of the Business for which the Company is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of personal information, or otherwise held or processed on its behalf and the Company is and has been in material compliance with such privacy policy. The Company has posted a privacy policy in a clear and conspicuous location on all Data Security Requirements in all material respects. Neither: (i) public websites owned or operated by the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementCompany.
(b) The Without limiting the generality of Section 4.14, the Company has not received any subpoenain the past three (3) years complied in all material respects with all applicable Laws regarding the collection, demandretention, inquiryuse and protection of personal information.
(c) Without limiting the generality of Section 4.16(b), the Company and, to the Knowledge of the Company, each other party thereto is in material compliance with the terms of all Material Contracts relating to data privacy, security or other written notice from breach notification (including provisions that impose conditions or restrictions on the collection, use, disclosure, transmission, destruction, maintenance, storage or safeguarding of personal information), if any.
(d) No Person (including any Governmental Authority investigatingAuthority) has, inquiring intoin the past three (3) years, or otherwise relating to (i) commenced any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, Action against the Company relating to the Company’s information privacy or data security practices relating to the personal information of consumers, including with respect to the access, disclosure or use of personal information of consumers maintained by or on behalf of the Company, or, (ii) to the Knowledge of the Company, threatened any actual or potential violation of any Data Security Requirements or any Data Security Incidentsuch Action, or under made any applicable industry standardscomplaint or investigation relating to such practices.
(ce) The execution, delivery and performance of this Agreement and the consummation of the contemplated transactions, including any transfer of personal information resulting from such transactions, will not violate the privacy policy of the Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. as it currently exists.
(f) The Company has established and complied at all timesimplemented policies, programs and procedures that are commercially reasonable, in all material respectscompliance with applicable industry practices and appropriate, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes including administrative, technical and physical safeguards, controls and measures that are designed safeguards to protect the confidentiality, integrity and security and integrity of data, including Personal Information, trade-secrets, proprietary personal information and confidential information, owned, controlled, maintained, held, or processed by for which the Company is the “controller” or any third party operating at similarly responsible under applicable Laws regarding the direction collection, retention, use and protection of personal information against unauthorized access, use, modification, disclosure or other misuse.
(g) Without limiting the generality of Section 4.15, to the Knowledge of the Company, the Business has not in the past three (ii3) includes disaster recoveryyears experienced any material loss, business continuitydamage, incident responseor unauthorized access, and disclosure, use or breach of security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems any personal information for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 of which the Company Disclosure Letteris the “controller” or similarly responsible under applicable Laws regarding the collection, to the knowledge retention, use and protection of Company (i) there have been no Data Security Incidents personal information or other adverse events otherwise held or incidents related to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company processed on its behalf that has not been adversely affected by any denial-of-service cured or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationotherwise resolved.
Appears in 1 contract
Privacy and Data Security. (a) The Company is in compliance with all Data Security Requirements Except as set forth on Schedules 3.22(a), the Group Companies comply, in all material respects. Neither: , with all applicable (i) the executionData Protection Laws, delivery or performance of this Agreement nor (ii) obligations relating to the consummation privacy, security or processing of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result Personal Data in any violation of any Contracts by which they are bound and (iii) Privacy Policies (clauses (i)-(iii) collectively, “Data Security RequirementPrivacy Requirements”).
(b) The To the Company’s Knowledge: (i) no Group Company has not received any subpoenasubpoenas, demand, inquirydemands, or other written notice notices from any Governmental Authority investigating, Entity investigating or inquiring into, or otherwise relating to into any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is the Privacy Requirements and (ii) no Group Company otherwise aware that it is has been under investigation by any Governmental Authority Entity for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No Privacy Requirements, and no notice, complaint, claim, enforcement action, inquiry, audit or litigation of any kind has been threatened in writing, served on, or initiated or otherwise asserted, against the a Group Company relating to any actual or potential alleging violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardsPrivacy Requirements.
(c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect Except as set forth on Schedule 3.22(c), the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has Group Companies have established and complied at all timesmaintain, and have maintained, physical, technical, and administrative safeguards, compliant in all material respects, respects with an information security program (the “Information Security Program”) that materially complies with all Data Security Privacy Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the operation, confidentiality, integrity, availability and security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the CompanyGroup Companies’ software, (ii) includes disaster recovery, business continuity, incident responsesystems, and security planswebsites that are involved in the collection or processing of Personal Data or confidential, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidentssensitive or business data. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
44 [[6907028]] (d) Except as disclosed in set forth on Schedule D.45 3.10(f)(ii), the Group Companies have not experienced any material failures, crashes, security incidents or data breaches related to Personal Data that would require, or has resulted in, notification of the Company Disclosure Letterindividuals, other affected parties, law enforcement or any Governmental Entity. There are no pending complaints, actions, fines, or other penalties initiated, pursued or, to the knowledge of Company (i) there have been no Data Security Incidents Company’s knowledge, threatened against the Group Companies in connection with any such failures, crashes, security breaches, unauthorized access, use, or disclosure, or other adverse events or incidents related to Personal Information incidents. (e) The execution, delivery and performance of this Agreement by the Company and the consummation of the Transactions will not cause, constitute, or result in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no Group Companies’ breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal InformationPrivacy Requirement.
Appears in 1 contract
Sources: Unit Purchase Agreement (White Mountains Insurance Group LTD)
Privacy and Data Security. (a) The Company is in compliance with all Data Security Requirements in all material respects. Neither: (iSection 3.26(a) the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any Disclosure Schedule contains a true and complete copy of the transactions contemplated by this Agreement or Company’s privacy policy regarding the Plan collection, use, and disclosure of Arrangement will result in any violation of any Data Security Requirementpersonal information.
(b) The Company has not received any subpoenacomplied at all times with the Company’s privacy policy, demandif any, inquiryand all applicable Laws regarding the collection, use, disclosure, storage, transfer, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation disposal of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardspersonal information.
(c) The Company is in compliance with the terms of all Contracts to which the Company is a party relating to data privacy, security, or breach notification (including provisions that impose conditions or restrictions on the collection, use, storage, transfer, or disposal of personal information).
(d) No Person (including any Governmental Authority) has taken commercially reasonable steps consistent commenced any Action relating to the Company’s information privacy or data security practices, including with Data Security Requirements respect to protect the integrity collection, use, transfer, storage, or disposal of personal information maintained by or on behalf of the Company, or, to the Company’s Knowledge, threatened any such Action, or made any complaint, investigation, or inquiry relating to such practices.
(e) The execution, delivery, and performance of this Agreement and the consummation of the transactions contemplated herein, including any transfer of personal information resulting from such transactions, will not violate any applicable Law or the privacy policy of the Company as it currently exists or as it existed at any time during which any personal information was collected or obtained by or on behalf of the Company or other privacy and data security of its information technology systems and to ensure that Personal Information in its possessionrequirements imposed on the Company, custody or control is protected against Data Security Incidents. any Person acting on the Company’s behalf, under any Contracts.
(f) The Company has established and complied at all timesimplemented commercially reasonable policies, in all material respectsprograms, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirementsand procedures, that is consistent with industry practice and: (i) includes including administrative, technical technical, and physical safeguards, controls and measures that are designed to protect the security and integrity of dataconfidentiality, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident responseintegrity, and security plansof personal information in its possession, procedures and facilitiescustody, and or control against unauthorized access, use, modification, disclosure, or other misuse.
(iiig) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basisnot, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 of the Company Disclosure Letter, to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possessionpast five (5) years, custody or control of the Companyexperienced any loss, including any system failures, breakdownsdamage, or viruses; (ii) no unauthorized access, disclosure, use, or breach or violation of security of any of personal information in the Company’s computer systems possession, custody, or Information Security Program has occurred control, or is threatened in writing, and there has been no unauthorized otherwise held or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to processed on the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationbehalf.
Appears in 1 contract
Privacy and Data Security. (a) The Company is in material compliance with the terms of all Data Security Requirements Company Contracts relating to data privacy, security or breach notification (including provisions that AGREEMENT AND PLAN OF MERGER 30 impose conditions or restrictions on the collection, use, disclosure, transmission, destruction, maintenance, storage or safeguarding of PII). To the Knowledge of the Company, HUM is in material compliance with the terms of all material respects. Neither: Contracts to which HUM is a party relating to data privacy, security or breach notification (i) including provisions that impose conditions or restrictions on the executioncollection, delivery use, disclosure, transmission, destruction, maintenance, storage or performance safeguarding of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementPII).
(b) The Company has not received notice of any subpoenaClaim or Action relating to the Company’s information privacy or data security practices, demandincluding with respect to the access, inquirydisclosure or use of personal information maintained by or on behalf of the Company, or other written notice from and to the Knowledge of the Company, no Person (including any Governmental Authority investigatingEntity) has threatened any such Claim or Action or conducted any investigation or inquiry with respect thereto. To the Knowledge of the Company, inquiring into, HUM has not received notice of any Claim or otherwise Action relating to any actual HUM’s information privacy or potential violation data security practices, including with respect to the access, disclosure or use of any Data Security Requirement personal information maintained by or any Data Security Incidenton behalf of HUM, nor is the Company otherwise aware that it is under investigation by and no Person (including any Governmental Authority for Entity) has threatened any actual such Claim or potential violation of Action or conducted any Data Security Requirement investigation or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardsinquiry with respect thereto.
(c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security Except as set forth in Section 4.13(c) of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at Disclosure Schedule, neither the direction Company nor, to the Knowledge of the Company, HUM, stores or retains any personally identifiable information (iias defined in NIST Special Publication 800-122) includes disaster recovery(“PII”), business continuityother than names, incident responseaddresses, phone numbers, email addresses and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests IP addresses or other device identifiers obtained in the ordinary course of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects’s business.
(d) Except as disclosed in Schedule D.45 To the Knowledge of the Company, neither the Company Disclosure Letternor HUM has experienced any loss, to the knowledge damage, or unauthorized access, disclosure, use or breach of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information security of any PII in the Company’s or HUM’s possession, custody or control of the Company, including any system failures, breakdownscontrol, or viruses; (ii) no breach otherwise held or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationprocessed on its behalf.
Appears in 1 contract
Sources: Merger Agreement (Avista Corp)
Privacy and Data Security. (a) The Company has a privacy policy regarding the collection, use and disclosure of personal information in connection with the operation of the Business for which the Company is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of personal information, or otherwise held or processed on its behalf and the Company is and has been in material compliance with such privacy policy. The Company has posted a privacy policy in a clear and conspicuous location on all Data Security Requirements in all material respects. Neither: (i) public websites owned or operated by the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementCompany.
(b) The Without limiting the generality of Section 4.09, the Company has not received any subpoenain the past three (3) years complied in all material respects with all applicable Laws regarding the collection, demandretention, inquiryuse and protection of personal information.
(c) Without limiting the generality of Section 4.12(b), the Company and, to the Knowledge of the Company, each other party thereto is in material compliance with the terms of all Material Contracts relating to data privacy, security or other written notice from breach notification (including provisions that impose conditions or restrictions on the collection, use, disclosure, transmission, destruction, maintenance, storage or safeguarding of personal information), if any.
(d) No Person (including any Governmental Authority investigatingAuthority) has, inquiring intoin the past three (3) years, or otherwise relating to (i) commenced any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, Action against the Company relating to the Company’s information privacy or data security practices relating to the personal information of consumers, including with respect to the access, disclosure or use of personal information of consumers maintained by or on behalf of the Company, or, (ii) to the Knowledge of the Company, threatened any actual or potential violation of any Data Security Requirements or any Data Security Incidentsuch Action, or under made any applicable industry standardscomplaint or investigation relating to such practices.
(ce) The execution, delivery and performance of this Agreement and the consummation of the contemplated transactions, including any transfer of personal information resulting from such transactions, will not violate the privacy policy of the Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. as it currently exists.
(f) The Company has established and complied at all timesimplemented policies, programs and procedures that are commercially reasonable, in all material respectscompliance with applicable industry practices and appropriate, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes including administrative, technical and physical safeguards, controls and measures that are designed safeguards to protect the confidentiality, integrity and security and integrity of data, including Personal Information, trade-secrets, proprietary personal information and confidential information, owned, controlled, maintained, held, or processed by for which the Company is the “controller” or any third party operating at similarly responsible under applicable Laws regarding the direction collection, retention, use and protection of the Companypersonal information against unauthorized access, (ii) includes disaster recoveryuse, business continuitymodification, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respectsdisclosure or other misuse.
(dg) Except as disclosed Without limiting the generality of Section 4.11, the Business has not in Schedule D.45 the past three (3) years experienced any loss, damage, or unauthorized access, disclosure, use or breach of security of any personal information for which the Company Disclosure Letteris the “controller” or similarly responsible under applicable Laws regarding the collection, to the knowledge retention, use and protection of Company (i) there have been no Data Security Incidents personal information or other adverse events otherwise held or incidents related to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationprocessed on its behalf.
Appears in 1 contract
Privacy and Data Security. (a) The Company Entities have a privacy policy regarding the collection, use and disclosure of personal information in connection with the operation of the Business for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of personal information, or otherwise held or processed on its behalf and each Company Entity is and has been in material compliance with such privacy policy. The Company Entities have posted a privacy policy in a clear and conspicuous location on all Data Security Requirements in all material respects. Neither: (i) public websites owned or operated by the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any Data Security RequirementCompany Entities.
(b) The To the Knowledge of the Company, each Company Entity has not received any subpoenain the past two (2) years complied in all material respects with all applicable Laws regarding the collection, demandretention, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation use and protection of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standardspersonal information.
(c) The To the Knowledge of the Company, each Company has taken commercially reasonable steps consistent Entity is in material compliance with Data Security Requirements the terms of all Material Contracts to protect which such Company Entity is a party relating to data privacy, security or breach notification (including provisions that impose conditions or restrictions on the integrity and security collection, use, disclosure, transmission, destruction, maintenance, storage or safeguarding of its information technology systems and to ensure that Personal Information in its possessionpersonal information), custody or control is protected against Data Security Incidents. The Company has established and complied at all timesif any.
(d) No Person (including any Governmental Authority) has, in all material respectsthe past two (2) years, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes commenced any Action against any Company Entity relating to any Company Entity’s information privacy or data security practices relating to the personal information of consumers, including with respect to the access, disclosure or use of personal information of consumers maintained by or on behalf of any Company Entity, or, (ii) to the Knowledge of the Company, threatened any such Action, or made any complaint or investigation relating to such practices.
(e) The execution, delivery and performance of this Agreement and the consummation of the contemplated transactions, including any transfer of personal information resulting from such transactions, will not violate the privacy policy of any Company Entity as it currently exists.
(f) The Company Entities have established and implemented policies, programs and procedures that are commercially reasonable, in material compliance with applicable industry practices and appropriate, including administrative, technical and physical safeguards, controls and measures that are designed safeguards to protect the confidentiality, integrity and security of personal information for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and integrity protection of datapersonal information against unauthorized access, including Personal Informationuse, trade-secretsmodification, proprietary information and confidential information, owned, controlled, maintained, held, disclosure or processed by other misuse.
(g) To the Company or any third party operating at the direction Knowledge of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company the Business has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 of the Company Disclosure Letter, to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information not in the possessionpast two (2) years experienced any loss, custody or control of the Company, including any system failures, breakdownsdamage, or viruses; (ii) no unauthorized access, disclosure, use or breach or violation of security of any personal information for which any Company Entity is the “controller” or similarly responsible under applicable Laws regarding the collection, retention, use and protection of the Company’s computer systems personal information or Information Security Program has occurred otherwise held or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal Informationprocessed on its behalf.
Appears in 1 contract
Sources: Merger Agreement (Acamar Partners Acquisition Corp.)
Privacy and Data Security. (a) The Each Group Company is subject to an information technology policy which includes, inter alia, a data security policy (the “Information Technology Policy”) regarding the collection, use, storage and disclosure of Personal Data, a true and correct copy of which has been provided to Buyer. Each Group Company is in material compliance with all Data Security Requirements in all material respects. Neither: applicable Laws regarding the collection, use, storage, disclosure and protection of Personal Data, and to the Company’s Knowledge, (i) the executiontheir IT Systems have not been subject to a material security breach, delivery or performance of this Agreement nor and (ii) the consummation of the Arrangement no Person has gained unauthorized access to or made any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation unauthorized use of any such Personal Data Security Requirementmaintained by any Group Company.
(b) The Company has not received any subpoenaNo material action, demandclaim, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, or otherwise relating to any actual or potential violation cause of any Data Security Requirement or any Data Security Incident, nor is the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No noticeaction, complaint, claimaudit, enforcement actionexamination, hearing, suit, Action, investigation (formal or litigation of informal) or arbitration is pending or, to the Company’s Knowledge, is threatened against any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Group Company relating to any actual alleged breaches of the Information Technology Policy or potential violation other breaches of applicable Law as they relate to Personal Data collected, used, stored or disclosed by any Group Company. The Group Companies have not received any written notice that they are or have been in material breach of any contractual obligation to limit its use of, secure or otherwise safeguard Personal Data Security Requirements and no such breach has occurred within the applicable statute of limitations for a claim arising out of such a breach. To the Company’s Knowledge, no Personal Data Processor has experienced a material security breach or made or been required to make any Data Security Incidentdisclosure, notification or take any other action under any applicable industry standards.
(c) The Company has taken Law in connection with any data breach with respect to any Personal Data of the Group Companies. Except as set forth on Schedule 3.19(b), the Group Companies have implemented commercially reasonable steps consistent with Data Security Requirements security measures intended to protect the integrity Personal Data they collect, use and security of its information technology store in their respective computer systems and other means of storage of data from illegal use by third parties. The Group Companies have in place and follow commercially reasonable procedures designed to ensure that all written contracts with Personal Information Data Processors require that such Personal Data Processors acquire, submit and store such Personal Data in its possessioncompliance with applicable Law and, custody or control is protected against Data Security Incidents. The Company has established and complied at all timeswhere applicable, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidents. The Company has conducted security assessments and tests of its computer systems on no less than an annual basis, including engaging independent third parties to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threats. To the knowledge of Company, the Information Security Program is adequate in all material respects.
(d) Except as disclosed in Schedule D.45 of the Company Disclosure Letter, to the knowledge of Company (i) there have been no Data Security Incidents or other adverse events or incidents related to Personal Information in the possession, custody or control of the Company, including any system failures, breakdowns, or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access to any Personal Information; (iii) the Company has not been adversely affected by any denial-of-service or other attack designed to materially interrupt operations or to interrupt access to the Company’s computer systems; and (iv) the Company has not notified nor has it been required to notify any person of any Data Security Incidents or other adverse events or incidents related to Personal InformationTechnology Policy.
Appears in 1 contract
Privacy and Data Security. (ai) The Since the Reference Date, the use and dissemination by the Company of any Personal Data is in compliance with all Data Security Requirements in all material respectsrespects with the Company’s privacy policies and terms of use, all applicable Information Privacy and Security Laws and all other Personal Data Obligations. Neither: (i) the execution, delivery or performance of this Agreement nor (ii) the consummation of the Arrangement or any of the transactions contemplated by this Agreement or the Plan of Arrangement will result in any violation of any No Personal Data Security Requirement.
(b) The Company has not received any subpoena, demand, inquiry, or other written notice from any Governmental Authority investigating, inquiring into, is stored or otherwise relating to any actual or potential violation of any Data Security Requirement or any Data Security Incident, nor is maintained outside the Company otherwise aware that it is under investigation by any Governmental Authority for any actual or potential violation of any Data Security Requirement or relating to any Data Security Incident. No notice, complaint, claim, enforcement action, or litigation of any kind has been threatened in writing, served on, initiated or otherwise asserted, against the Company relating to any actual or potential violation of any Data Security Requirements or any Data Security Incident, or under any applicable industry standards.
(c) The Company has taken commercially reasonable steps consistent with Data Security Requirements to protect the integrity and security of its information technology systems and to ensure that Personal Information in its possession, custody or control is protected against Data Security Incidents. The Company has established and complied at all times, in all material respects, with an information security program (the “Information Security Program”) that materially complies with all Data Security Requirements, that is consistent with industry practice and: (i) includes administrative, technical and physical safeguards, controls and measures that are designed to protect the security and integrity of data, including Personal Information, trade-secrets, proprietary information and confidential information, owned, controlled, maintained, held, or processed United States by the Company or any third party operating at the direction of the Company, (ii) includes disaster recovery, business continuity, incident response, and security plans, procedures and facilities, and (iii) is designed to detect and protect against Data Security Incidentsparty. The Company has conducted not engaged in cross-border processing of Personal Data. True and complete copies of all privacy policies that have been used by the Company since the Reference Date have been provided to Buyer. The Company has consistently posted a privacy policy in a clear and conspicuous location on all websites and any mobile applications owned or operated by the Company.
(ii) The Company does not Collect or Use Personal Data from any Person in any manner other than as described in the Contracts and privacy policies delivered to Buyer.
(iii) The Company maintains policies and procedures regarding data security assessments and tests of its computer systems on no less than an annual basisprivacy and maintains administrative, including engaging independent third parties technical and physical safeguards that are commercially reasonable and, in any event, in compliance with all applicable Information Privacy and Security Laws and all Contracts to test its computer systems for vulnerabilities, Data Security Incidents, and cyber threatswhich the Company is bound. To Since the knowledge of CompanyReference Date, the Information Security Program is adequate Company has complied in all material respectsrespects with the terms of all Contracts to which the Company is a party relating to data privacy, security or breach notification (including provisions that impose conditions or restrictions on the collection, use, disclosure, transmission, destruction, maintenance, storage, or safeguarding of Personal Data).
(div) Except as disclosed in Schedule D.45 of At any time since the Company Disclosure LetterReference Date, to the knowledge of Company (i) there have been no Data security breaches relating to, or violations of any security policy or Information Privacy and Security Incidents Law regarding, or any unauthorized access, disclosure, or use of, any data or information used by the Company, including Personal Data. No written notice has been provided to the Company by a third party vendor or any other adverse events or incidents related person of any security breach relating to Personal Information Data. Since the Reference Date, the Company has not experienced a loss or unauthorized disclosure, use, or breach of privacy or security of any Personal Data in the possession, custody or control of the Company, Company that would have required notice to any third Person (including any system failures, breakdowns, Governmental Authority or viruses; (ii) no breach or violation of any of the Company’s computer systems or Information Security Program has occurred or is threatened in writing, and there has been no unauthorized or illegal use of or access parties to any Personal Information; Contract) under any applicable Law. No Person (iiiincluding any Governmental Authority) the Company has not been adversely affected by commenced any denial-of-service or other attack designed to materially interrupt operations or to interrupt access Action relating to the Company’s computer systemsinformation privacy or data security practices, or to the Knowledge of the Company, threatened any such Action or made any complaint, investigation, or inquiry relating to such practices.
(v) The Company does not (x) have or solicit any customers in the European Economic Area, or (y) knowingly process, transmit, or store any Personal Data of any Persons located in the European Economic Area.
(vi) The Company has taken all required steps to limit access to Personal Data to: (x) those Company personnel and third-party vendors providing services to or on behalf of the Company who have a need to know such Personal Data in the execution of their duties to the Company; and (ivy) such other Persons permitted to access such Personal Data in accordance with the privacy policies and terms of use, all applicable Information Privacy and Security Laws and all Contracts to which the Company is bound.
(vii) The Company maintains a written technical information security program that contains commercially reasonable administrative, technical and physical safeguards (including encryption) compliant in all material respects with applicable Information Privacy and Security Laws (the “Security Program”). The Company’s Security Program is designed to: (v) protect the integrity and confidentiality of Personal Data; (w) protect against reasonably anticipated threats or hazards to the security of Personal Data; (x) protect against the unauthorized access, disclosure or use of Personal Data; (y) address computer and network security; and (z) provide for the secure destruction and disposal of Personal Data. The Security Program has not notified nor has it been updated as required to notify any person of any Data by all applicable Information Privacy and Security Incidents Laws. All third-party vendors or other adverse events or incidents related persons with access to Personal InformationData have entered into contracts or written agreements with the Company requiring that such vendors or persons maintain a substantially similar security program to the extent required under applicable Information Privacy and Security Laws.
Appears in 1 contract