DPA

909Cyber

This Data Protection Addendum (“DPA”), effective the date of the last signature, forms part of the order form, contract and/or agreement (the “Agreement”) between _______ (“CUSTOMER”) and 909Cyber, Inc. (“909Cyber”), and reflects the parties’ agreement with respect to the processing of CUSTOMER Data (defined below) by 909Cyber under the Agreement.

This DPA includes this document, Annex 1 (Description of the Processing), Annex 2 (Technical and Organizational Measures), and Annex 3 (Subcontractors) and (where applicable) the SCCs. Unless otherwise defined herein, capitalized terms in this DPA will have the same meaning ascribed to them in the Agreement.

1. APPLICATION AND SCOPE

1.1 Scope. This DPA applies to the processing of CUSTOMER Data by 909Cyber for the provision of the Services in connection with the Agreement. The subject matter, nature, purpose and duration of processing under this DPA, and the types of personal data and the categories of data subjects, are described in Annex 1 to this DPA.

1.2 Roles. 909Cyber shall process CUSTOMER Data as a processor or service provider (as applicable) and, as such, shall collect, use, disclose, store, delete or otherwise process CUSTOMER Data solely on behalf of and at the direction of CUSTOMER, strictly for the purpose of providing the Services as specified in the Agreement. CUSTOMER may be a controller itself or a processor or service provider (as applicable) acting on behalf of a third-party controller.

1.3 Instructions. CUSTOMER instructs 909Cyber to process CUSTOMER Data for the following purposes: (a) processing in accordance with the Agreement; (b) where applicable, processing initiated by CUSTOMER’s authorized users in their use of the Services; and (c) processing to comply with other reasonable instructions provided by CUSTOMER (e.g., via email or support tickets) where such instructions are consistent with the terms of the Agreement and/or Data Protection Laws.

1.4 Restrictions. 909Cyber agrees that it shall not: (a) retain, use, disclose or otherwise process CUSTOMER Data for any purpose other than the business purposes specified under the Agreement or as otherwise permitted by applicable Data Protection Laws; (b) “sell” CUSTOMER Data within the meaning of applicable Data Protection Laws or share CUSTOMER Data for the purposes of targeted or cross-context behavioral advertising; or (c) use any CUSTOMER Data received in connection with the Agreement outside of the direct relationship between CUSTOMER and 909Cyber or to provide services to another person or entity, except as permitted under the Agreement and applicable Data Protection Laws.

2. 909CYBER OBLIGATIONS

2.1 Compliance. 909Cyber shall comply with all Data Protection Laws applicable to it and agrees to process CUSTOMER Data only in accordance with CUSTOMER’s instructions. 909Cyber will immediately inform CUSTOMER if: (a) in its opinion, an instruction from CUSTOMER infringes Data Protection Laws; (b) it can no longer meet its obligations under Data Protection Laws and this DPA; and/or (c) if 909Cyber is required by applicable laws to process CUSTOMER Data outside the scope of CUSTOMER’s instructions, in which case 909Cyber shall inform CUSTOMER of the legal requirement before such processing.

2.2 Appointment of Subcontractors. CUSTOMER provides a general written authorization that 909Cyber may engage Subcontractors to process CUSTOMER Data on its behalf. 909Cyber provides a list of its current Subcontractors, if any, at Annex 3, indicating their role in processing activities and the jurisdictions wherein each Subcontractor stores or otherwise processes CUSTOMER Data. 909Cyber shall make an updated list of its Subcontractors available to CUSTOMER upon request. 909Cyber shall inform CUSTOMER in writing with at least thirty (30) days prior notice of any intended changes concerning the addition or replacement of any Subcontractor. 909Cyber shall ensure that all of its Subcontractors are bound by agreements that contain the same data protection obligations for CUSTOMER Data as those that apply to 909Cyber under this DPA. 909Cyber shall be liable to CUSTOMER for the performance of its Subcontractors' data protection obligations to the same extent as if it performed those obligations.

2.3 Right to Object to Subcontractors. CUSTOMER may reasonably object to 909Cyber’s use of any new or replacement Subcontractor. Upon CUSTOMER’s objection, 909Cyber will use reasonable efforts to make available to CUSTOMER a change in the Services or recommend a commercially reasonable change to CUSTOMER’s configuration or use of the Services to avoid the processing of CUSTOMER Data by the objected-to Subcontractor. If 909Cyber is unable to make such change within a reasonable period of time, CUSTOMER may terminate the Agreement or the affected part of the Services.

2.4 Confidentiality. 909Cyber shall ensure that CUSTOMER Data is processed only by authorized personnel and, unless otherwise permitted by this DPA, shall not disclose CUSTOMER Data to any third party. 909Cyber shall ensure that persons that it authorizes to process CUSTOMER Data (including its staff, agents and Subcontractors) are subject to a duty of confidentiality that survives the termination of their employment and/or contractual relationship.

2.5 Security. 909Cyber shall maintain a comprehensive information security program that includes administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of CUSTOMER Data that meets industry standards commensurate with 909Cyber’s activities and the volume and sensitivity of CUSTOMER Data. Such measures shall meet at least the minimum security levels required under applicable Data Protection Laws and the technical and organizational measures set out in Annex 2 to this DPA. 909Cyber shall regularly review compliance with these measures and will not materially decrease the overall security of the Services during the term of the Agreement.

2.6 Audits and Third-Party Security Certifications. 909Cyber shall use external auditors to verify the adequacy of its security measures, including the security of the physical data centers from which 909Cyber provides the Services. This audit shall: (a) be performed at least annually; (b) be performed according to generally accepted industry standards; (c) be performed by independent third party security professionals at 909Cyber’s selection and expense; and (d) result in the generation of an audit report (“Audit Report”). 909Cyber agrees to make its Audit Report available to CUSTOMER upon written request no more than once per year and subject to the confidentiality obligations set forth in the Agreement (or a separate non-disclosure agreement, if necessary) and to respond to any follow-up questions regarding 909Cyber’s security measures. While it is the parties’ intention to ordinarily rely on the provision of Audit Reports and responses to follow-up questions to verify 909Cyber’s compliance with this DPA, if such information is not reasonably sufficient to verify 909Cyber’s compliance with this DPA and Data Protection Laws, CUSTOMER (or its authorized representative) may conduct an audit or inspection of 909Cyber’s data security infrastructure and procedures, provided that any such audit or inspection shall be subject to not less than thirty (30) days’ prior written notice, take place at a mutually agreeable date and time, and not be unreasonably disruptive to 909Cyber’s business operations.

2.7 Incident Management and Notification. If 909Cyber becomes aware of a Security Incident, 909Cyber shall:

(a) without undue delay, and in any event within 48 hours, notify CUSTOMER by email to the email address on file;

(b) conduct a thorough investigation of such Security Incident, document the steps for any needed remediation, provide the results of its analysis to CUSTOMER promptly following the investigation, and implement the needed remediation, including reconstruction or restoration of any affected CUSTOMER Data;

(c) assign one or more 909Cyber personnel, and communicate to CUSTOMER the name(s) of such 909Cyber personnel, to facilitate and respond to issues related to the Security Incident and obligations under the Agreement and this DPA.

2.8 Data Subject Requests. Taking into account the nature of the processing, and to the extent CUSTOMER cannot respond to Data Subject requests through functionality made available via the Services, 909Cyber shall provide upon CUSTOMER’s reasonable request commercially reasonable assistance, insofar as such assistance is required under applicable Data Protection Laws, to enable CUSTOMER to respond to any request from a Data Subject seeking to exercise their rights under applicable Data Protection Laws, including the rights of access, correction, restriction, objection, erasure or data portability (as applicable).

2.9 Government Requests. 909Cyber shall not disclose CUSTOMER Data to any law enforcement agency or government authority (“Government Authority”) unless instructed by CUSTOMER, or as necessary to comply with applicable laws or a valid and binding order of a Government Authority, such as a subpoena or court order. If a Government Authority requests access to CUSTOMER Data, 909Cyber shall: (a) immediately notify CUSTOMER to allow CUSTOMER to seek a protective order or other appropriate remedy; (b) inform the Government Authority that 909Cyber processes the data on behalf of CUSTOMER and is not authorized to disclose the data; (c) attempt to redirect the Government Authority to CUSTOMER; and (d) not provide access to the data unless and until authorized by CUSTOMER. If 909Cyber is legally prohibited from notifying CUSTOMER of a Government Authority request, 909Cyber will notify CUSTOMER of its inability to provide such notification, and such inability shall not constitute a breach of this DPA by 909Cyber. In such circumstances, CUSTOMER will have the right to suspend 909Cyber’s processing of any new CUSTOMER Data pending resolution of the governmental request.

2.10 Data Protection Impact Assessments. Upon CUSTOMER’s reasonable written request, and to extent required under applicable Data Protection Law, 909Cyber shall provide CUSTOMER with reasonable cooperation and assistance needed to fulfill CUSTOMER’s obligation to carry out a data protection or privacy impact or risk assessment and/or consult with data protection authorities related to CUSTOMER’s use of the Services.

2.11 Return or Deletion of CUSTOMER Data. Upon completion of the Services, 909Cyber shall notify CUSTOMER and, upon CUSTOMER’s written request, return or delete all CUSTOMER Data and copies of such data in its custody or control, unless and only to the extent applicable law prevents it from doing so, in which case 909Cyber shall promptly notify CUSTOMER of any CUSTOMER Data it intends to retain and the legal basis for its retention.

3 INTERNATIONAL TRANSFERS

3.1 International Data Transfers. 909Cyber shall not transfer or process CUSTOMER Data in any country other than the country in which the CUSTOMER Data was first collected or provided to 909Cyber (and not permit CUSTOMER Data to be so transferred or processed) until it first takes all such measures as are necessary to ensure such transfers are made in compliance with Data Protection Laws.

3.2 Standard Contractual Clauses. To the extent that the transfer of CUSTOMER Data from CUSTOMER (or a Permitted Affiliate) to 909Cyber involves a Restricted Transfer, the SCCs shall be incorporated by reference and form an integral part of this DPA with 909Cyber as the "data importer" and CUSTOMER (or the Permitted Affiliate) as the "data exporter". For the purposes of the SCCs: (a) the Module Two terms shall apply where CUSTOMER (or the Permitted Affiliate) is a controller and the Module Three terms shall apply where CUSTOMER (or the Permitted Affiliate) is a processor; (b) in Clause 9, Option 2 shall apply and the time period for notification of new Subcontractors shall be as specified in Section 2.2 of the DPA; (c) in Clause 11, the optional language shall be deleted; (d) in Clause 17, Option 1 shall apply and the SCCs shall be governed by Irish law; (e) in Clause 18(b), disputes shall be resolved before the courts of Ireland; and (f) the Annexes of the SCCs shall be populated with the relevant information included at Appendix 1 of this DPA.

3.3 UK Transfers. To the extent that the CUSTOMER Data described in Section 3.2 is subject to the UK GDPR, the SCCs shall be amended by the International Data Transfer Addendum issued by the UK Information Commissioner's Office, which shall be incorporated by reference as follows: (i) in Table 1, the parties’ details are included at Appendix 1 of this DPA; (ii) in Table 2, the selected modules and clauses are set out in Section 3.2; (iii) in Table 3, the appendix information is included at Appendix 1 of this DPA; and (iv) in Table 4, ‘exporter' is selected.

3.4 Swiss Transfers. To the extent that the CUSTOMER Data described in Section 3.2 is subject to the Swiss DPA, the SCCs shall apply in accordance with Section 3.2 and the following modifications: (a) references to ‘Regulation (EU) 2016/679’ shall be interpreted as references to the Swiss DPA; (b) references to specific articles of ‘Regulation (EU) 2016/679’ shall be replaced with the equivalent article or section of the Swiss DPA; (c) references to ‘EU’, ‘Union’ and ‘Member State’ shall be replaced with ‘Switzerland’; (d) Clause 13(a) and Part C of Annex 2 shall not be used and the ‘competent supervisory authority’ shall be the Swiss Federal Data Protection Information Commissioner; (e) references to the ‘competent supervisory authority’ and ‘competent courts’ shall be replaced with the ‘Swiss Federal Data Protection Information Commissioner’ and ‘applicable courts of Switzerland’; (f) in Clause 17, the SCCs shall be governed by the laws of Switzerland; and (g) in Clause 18(b), disputes shall be resolved before the competent courts of Switzerland.

3.5 Alternative Transfer Mechanism. In the event that the SCCs as implemented in accordance with Section 3 and the other protections as described in this DPA cannot be relied on to lawfully transfer CUSTOMER Data to 909Cyber in compliance with applicable European Data Protection Laws, then 909Cyber agrees to reasonably cooperate with CUSTOMER to implement such additional measures or alternative transfer mechanisms as may be required to ensure the lawful transfer of CUSTOMER Data to 909Cyber.

4. GENERAL TERMS

4.1 Parties and Permitted Affiliates. CUSTOMER enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Permitted Affiliates, thereby establishing a separate DPA and separate set of Standard Contractual Clauses between 909Cyber and each such Permitted Affiliate subject to the Agreement.

4.2 Legal Effect. This DPA is an addendum to and is incorporated into the Agreement between 909Cyber and CUSTOMER. Except for changes made by this DPA, the Agreement remains unchanged and in full force and effect. This DPA supersedes and replaces all prior or contemporaneous representations, understandings, agreements, or communications between 909Cyber and CUSTOMER, whether written or verbal, regarding the subject matter of this DPA, including any data processing addenda previously entered into between CUSTOMER and 909Cyber.

4.3 Conflict. If there is a conflict between any provision in this DPA and any provision in the Agreement, this DPA controls and takes precedence. Where applicable, if there is a conflict between any provision of the SCCs and this DPA, the SCCs control and take precedence.

4.4 Counterparts. This DPA may be executed in any number of counterparts, each of which will be deemed to be an original and all of which taken together will comprise a single instrument. This DPA may be delivered by electronic document format (e.g. PDF or Adobe Sign), and electronic copies of executed signature pages are binding as originals.

4.5 Limitations of Liability. 909Cyber acknowledges and agrees that: (a) it shall be liable for any loss or misuse of CUSTOMER Data to the extent such loss or misuse results from any failure of 909Cyber (or its Subcontractors) to comply with its obligations under this DPA and/or Data Protection Laws; and (b) any claims arising under or in connection with this DPA and/or Data Protection Laws shall be subject to the exclusions and limitations set forth in the Agreement; and (c) a material breach of this DPA by 909Cyber shall constitute a material breach of the Agreement, in which event, and without prejudice to any other right or remedy available to it, CUSTOMER may elect to immediately terminate the Agreement and/or this DPA.

4.6 Survival. This Addendum shall survive termination or expiration of the Agreement.

5. DEFINITIONS

In this DPA, the following terms have the meaning given to them below:

(a) The terms “controller”, “processor”, and “service provider” have the meanings given to them in applicable Data Protection Laws.

(b) “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control” means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.

(c) “Data Protection Laws” means all data protection and privacy laws and regulations applicable to the processing of CUSTOMER Data under the Agreement, including but not limited to European Data Protection Laws, US Data Protection Laws and applicable provincial and federal privacy laws in Canada.

(d) “Data Subject” means any individual whose Personal Data is processed by 909Cyber on behalf of CUSTOMER under the Agreement, and includes “data subject” as that term is defined in the GDPR and “consumer” as that term is defined in US Data Protection Laws.

(e) “Europe” means, for the purposes of this DPA, the European Economic Area and its Member States, Switzerland and the United Kingdom.

(f) “European Data Protection Laws” means all data protection and privacy laws and regulations in Europe applicable to the processing of CUSTOMER Data under the Agreement, including (i) the EU General Data Protection Regulation (“GDPR”); (ii) any applicable national implementations of the GDPR; (iii) the GDPR as it forms part of UK law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018 (together, the “UK GDPR”); and (iv) the Swiss Federal Data Protection Act of 19 June 1992 and its Ordinance (“Swiss DPA”); in each case as may be amended, superseded or replaced from time to time.

(g) “CUSTOMER Data” means any data provided by CUSTOMER or a Permitted Affiliate to 909Cyber for the purpose of receiving the Services that is either: (i) Personal Data; or (ii) information that 909Cyber is required to treat as confidential under the Agreement.

(h) “Permitted Affiliates” means any CUSTOMER Affiliates that are permitted to use the Services pursuant to the Agreement but have not signed their own separate agreement with 909Cyber.

(i) “Personal Data” means any information that relates to an identified or identifiable person and which is protected as "personal data", "personal information" or "personally identifiable information" under applicable Data Protection Laws.

(j) “Process” means to perform any operation or set or operations on Personal Data, and includes “process” as that term is defined in the GDPR, and "processes", “processing” and "processed" will be interpreted accordingly.

(k) “Restricted Transfer” means a transfer of personal data originating from Europe to a country that does not provide an adequate level of protection for personal data within the meaning of applicable European Data Protection Laws.

(l) “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, any CUSTOMER Data.

(m) “Services” means the services provided by 909Cyber to CUSTOMER under the Agreement.

(n) “Standard Contractual Clauses” or “SCCs” mean the standard contractual clauses as approved by the European Commission pursuant to its decision 2021/914 of 4 June 2021 and available at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN, or any updated version thereof.

(o) “Subcontractor” means any third party engaged by 909Cyber that processes CUSTOMER Data for the purpose of providing the Services to CUSTOMER, including 909Cyber Affiliates, and includes “subprocessor” and “subcontractor” as those terms are defined in applicable Data Protection Laws.

(p) “US Data Protection Laws” means all federal and state data protection and privacy laws and regulations in the United States applicable to the processing of CUSTOMER Data under the Agreement, including (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and any implementing regulations relating to the same; (ii) the Virginia Consumer Data Protection Act; (iii) the Colorado Privacy Act; (iv) the Utah Consumer Privacy Act; and (v) the Connecticut Data Privacy Act; in each case as may be amended, superseded or replaced from time to time.

The parties have caused this DPA to be executed by their authorized representatives effective as at the date both parties execute this DPA:

909Cyber, Inc.:

____________________________________

_________________________________________

Signature of Authorized Representative

________________________________________

Print Name

________________________________________

Title

________________________________________

Date

________________________________________

Address

CUSTOMER:

_________________________________________

_________________________________________

Signature of Authorized Representative

________________________________________

Print Name

________________________________________

Title

________________________________________

Date

________________________________________

Address

Annex 1: Description of the Processing

This Annex describes the parties, the categories of data subjects, and the processing of personal data by 909Cyber in connection with the Services.

Annex 1(A): List of parties

Refer to https://www.909cyber.com/legal/shield/sub-processors

Annex 1(B): Description of the processing / transfer

Description

Categories of Data Subjects:

The categories of Data Subjects are defined in the Agreement and may include, where applicable and appropriate for the Services:

employees and contractors of the data exporter; prospective employees and contractors of the data exporter, and other end-users.

Categories of Personal Data:

The categories of Personal Data processed are defined in the Agreement and may include, where applicable and appropriate for the Services:

Contact details (such as name, email address, telephone number);

Unique identifiers and account profile information; and

Device information and log data (such as geo-location, email, calendars, contacts, IP addresses, event and product usage data).

Sensitive data transferred (if applicable) and applied restrictions or safeguards:

The parties do not anticipate the transfer or processing of sensitive data (i.e., racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation).

Frequency of the transfer:

Continuous

Nature of the processing:

Collection, storage, organization, modification, retrieval, disclosure, communication and other uses in performance of the Services as set forth in the Agreement.

Purpose(s) and subject matter of the data transfer and further processing:

Processing activities in performance of the Services as set forth in the Agreement.

Period and duration for which the personal data will be processed and retained, or, if that is not possible, the criteria used to determine that period:

Personal Data will be processed for the duration of the Agreement and will be deleted in accordance with Section 2.11 of the DPA.

Standard Contractual Clauses Module

Annex 1(C): Competent supervisory authority

For the purposes of the SCCs (where applicable), the supervisory authority is the Irish Data Protection Commissioner.

Annex 2: Technical and Organizational Measures

All processors are required to implement and maintain an information security program that implements, as is commercially reasonable given the nature, scope, context and purposes of processing, the following controls to ensure appropriate technical and organizational measures are adopted to protect CUSTOMER Data. Any reference to 909Cyber includes 909Cyber, its Subcontractors, and their respective personnel.

1. Encryption

909Cyber shall:

  1. implement and maintain encryption of CUSTOMER Data while in transit and at rest, in accordance with industry standards for strong encryption;
  2. ensure that the encryption algorithm and its parameterization (e.g., key length and operating mode) conform to the state-of-the-art and can be considered robust against cryptanalysis;
  3. ensure that the encryption algorithm is implemented correctly and by properly maintained software without known vulnerabilities, the conformity of which to the specification of the algorithm chosen has been verified, (e.g., by certification);
  4. not hold or have access to encryption keys if such encryption keys are managed by CUSTOMER to encrypt CUSTOMER Data at rest or in transit; and

2. Authentication

Where 909Cyber manages user authentication controls for 909Cyber personnel, 909Cyber must:

  1. enforce minimum password complexity, such as requiring passwords to be case sensitive, or requiring passwords to contain a minimum of eight characters and a combination of upper-case letters, lower-case letters, numbers, and/or special characters;
  2. require regular change of passwords at predetermined intervals, and which limit reuse;
  3. ensure that passwords are never stored in clear-text and are encrypted in transit and at rest;
  4. require initial password to be changed after the first login; and
  5. require multi-factor authentication for privileged access, including access to critical and/or production resources.

3. General Security Maintenance

909Cyber must:

  1. have information security policies based on recognized industry standards;
  2. conduct regular vulnerability scans, web application scans, and penetration tests;
  3. apply system hardening methods in securing 909Cyber systems;
  4. logically isolate and encrypt CUSTOMER Data;
  5. ensure workstations and servers used in management and provisioning of the Services are patched and secured with anti-malware protection and endpoint security software;
  6. remedy vulnerabilities in a timely manner according to criticality;
  7. patch all systems and software regularly according to industry best practices; and
  8. use secure coding practices when developing applications and application programming interfaces.

4. Access Control

909Cyber must:

  1. implement access control policies and procedures that address onboarding, off-boarding, transition between roles, regular access reviews, limitations and usage control of administrator privileges, and inactivity timeouts;
  2. identify and segregate conflicting duties and areas of responsibility, such as separation of duties, to reduce opportunities for unauthorized or unintentional modification or misuse;
  3. maintain a current and accurate inventory of computer accounts;
  4. review the inventory of computer accounts on a regular basis to identify dormant, fictitious or unused accounts;
  5. enforce principles of “least privilege” and “need to know” and creation of differentiated access profiles based on security groups, access control lists and role-based access within operational and corporate environments;
  6. review user access rights on a regular basis to identify excessive privileges;
  7. track, log and audit authorization requests on a regular basis;
  8. remove access for employee upon termination or change of employment; and
  9. enforce a limit of login attempts (i.e., automatic account locking) and concurrent sessions.

5. Security Awareness and Security Contact

909Cyber must:

  1. ensure that all persons employed or retained to perform the Services receive adequate privacy and security awareness training, annually, and supervision at a level and in substance that is appropriate to that person’s position and 909Cyber’s obligations under this DPA (such training should address topics including: data protection, confidentiality, social engineering, password policies, and overall security responsibilities);
  2. not permit any person that 909Cyber engages or uses to access or obtain any CUSTOMER Data unless that person is contractually bound to 909Cyber in writing to keep CUSTOMER Data confidential on terms no less protective than the terms applicable to 909Cyber under the Agreement and this DPA;
  3. appoint one or more security officers responsible for coordinating and monitoring security requirements and procedures; and
  4. provide the contact information for the individual(s) who will coordinate compliance by 909Cyber on matters related to this DPA.

6. Log Generation and Retention

909Cyber must:

  1. generate and retain logs that are sufficiently detailed to determine who did what and when for a period of 2 weeks online;
  2. ensure that write access to logging data is strictly prohibited, and that logging facilities and log information are protected against tampering and unauthorized access through use of access controls and security measures; and
  3. correlate, monitor, and alert on logs.

7. Incident Response and Management

909Cyber must:

  1. have an incident management plan and an incident response plan;
  2. verify logs at least once every six months to propose remediation efforts if necessary; and
  3. review and test both incident management and incident response plans annually; and
  4. maintain a record of security breaches with a description of the breach, the time period, the consequences of the breach, the name of the reporter, and to whom the breach was reported, and the procedure for recovering data.

If there is an incident involving CUSTOMER Data, 909Cyber must:

  1. retain investigation reports related to any security investigation for a period of 2 years after the investigation is completed or otherwise provide such reports to CUSTOMER for retention; and
  2. provide reasonable investigative support to CUSTOMER, including, providing logs, electronic copies of documents and maintain legal holds, as required for litigation and investigative purposes.

8. Business Continuity, Disaster Recovery and Backup Plans

909Cyber must:

  1. have a business continuity plan and a disaster recovery plan;
  2. conduct regular backups of critical data;
  3. maintain redundant storage and procedures for recovering data that are designed to attempt to reconstruct CUSTOMER Data in its original or last-replicated state from before the time it was lost or destroyed;
  4. review and test business continuity, disaster recovery, and backup plans and procedures regularly.

9. Asset Management and Disposal

909Cyber must:

  1. maintain an inventory of CUSTOMER assets and classify such assets to help identify them and to allow for access to be appropriately restricted;
  2. use secure methods when disposing of CUSTOMER Data assets;
  3. maintain an inventory of all media on which CUSTOMER Data is stored;
  4. impose restrictions on printing CUSTOMER Data and have procedures for disposing of printed materials that contain such data; and
  5. maintain records of CUSTOMER Data asset disposals.

10. Security Screening

909Cyber must:

  1. maintain and update a record of personnel authorized to access CUSTOMER systems that contain CUSTOMER Data;
  2. ensure that where more than one individual has access to systems containing CUSTOMER Data, the individuals have separate identifiers/log-ins;
  3. identify the personnel who may grant, alter or cancel authorized access to data and resources; and
  4. screen all 909Cyber personnel prior to 909Cyber authorizing access to CUSTOMER Data or 909Cyber systems.

11. Supply Chain

909Cyber must:

  1. have in place a Change Management Policy and monitor changes to in-scope systems to ensure that changes follow the process and to mitigate the risk of un-detected changes to production;
  2. maintain a supply chain review program that assesses the security practices of suppliers, subcontractors and subprocessors (collectively, “Suppliers”) involved in the provision of Services and identifies and addresses any risks that arise from this assessment; and
  3. promptly notify CUSTOMER of any breach of security of a supplier, subcontractor or subprocessor affecting, or potentially affecting, the security or confidentiality of CUSTOMER Data.

12. Isolation Controls

909Cyber must:

  1. implement and maintain the logical isolation of CUSTOMER Data, even in the case of equipment or technology failure;
  2. implement, where supported by available technology, the logical isolation of audit records related to CUSTOMER Data and activities, even in the case of equipment or technology failure;
  3. segregate tenancy traffic from management network traffic; and
  4. not use CUSTOMER Data for test or development purposes without the prior written approval of CUSTOMER.

15. Technical Controls

909Cyber must:

  1. implement firewalls, web application firewalls, distributed denial of service prevention, and intrusion prevention systems to control traffic flow to and from 909Cyber’s systems; and
  2. secure remote access to 909Cyber’s systems by 909Cyber personnel and contractors (e.g. through the use of a VPN).

13. Threat and Risk Assessments

909Cyber must:

  1. conduct threat and risk assessments on any part of the 909Cyber’s systems that is new, or has been materially changed since the last threat and risk assessment was conducted;
  2. ensure that equipment is protected to reduce the risks from environmental threats, hazards, and opportunities for unauthorized access;
  3. perform customer privacy assessments prior to introducing any new feature or service that involves processing of CUSTOMER Data; and
  4. support CUSTOMER in completing security threat and risk assessments.

14. Use of CUSTOMER Systems

Where 909Cyber will be accessing or otherwise using CUSTOMER systems, use of CUSTOMER Systems by 909Cyber or its personnel (including subcontractors) must be restricted to activities necessary for the provision of the Services. CUSTOMER reserves the right to not make any particular facility, system, network or device available to 909Cyber unless 909Cyber or its individual personnel (as applicable) agree to any additional terms and conditions acceptable to CUSTOMER.

Annex 3: Subcontractors

A publicly listed web page that accurately and fully identifies all Subcontractors 909Cyber uses in connection with the Services, their role in processing activities, and the location from where they access and process CUSTOMER Data:

https://www.909cyber.com/legal/shield/sub-processors