Hazeltree Data Security Addendum

DATA SECURITY ADDENDUM

(“ADDENDUM”)

General Security Requirements.

Hazeltree shall maintain a written security program designed to: (i) protect against any anticipated threats or hazards to the security or integrity, and the unavailability, of the Licensee Data, the SaaS Services, and Hazeltree’s systems; (ii) protect against unauthorized or unlawful access to or use of the Licensee Data, the SaaS Services, and Hazeltree’s systems and other information that is otherwise obtained by Hazeltree in connection with this Agreement, or to which Hazeltree has access in the course of performing its obligations under this Agreement; (iii) protect against accidental loss or destruction of, damage to, or disclosure, modification, or deletion of the Licensee Data; (iv) ensure that the Licensee Data, the SaaS Services, and Hazeltree’s systems and any associated hardware, system, or software are housed in physically secure premises with adequate fire protection and facility access controls; and (v) ensure the secure and proper disposal of Licensee Data. Such security program will conform to this Addendum and is further described in Hazeltree’s most recently completed ISO 27001 certificate (“Audit Reports”).

Hazeltree is responsible for securing the hosted environment, including its systems, operating systems, networks, and applications[DP1] (#_msocom_1) .

Hazeltree shall provide capability to integrate Licensee’s corporate identity solution with an industry standard identity authentication via SAML 2.0.

Hazeltree shall protect from unauthorized disclosureexposure, via robust encryption, all Licensee Data using commercially reasonable algorithms and key lengths both: (i) while being transmitted outside of a secured data center; and (ii) at-rest in Hazeltree’s systems (e.g., AES 256 bit).

Hazeltree shall only use Licensee Data in accordance with the express terms of this Agreement. Hazeltree shall not use, modify, or delete Licensee Data except as expressly set forth in this Agreement or agreed to in writing by Licensee. Hazeltree shall permanently delete or destroy all Licensee Data in a secure manner upon termination of this Agreement, subject to any requirements to return Licensee Data, or copies thereof, to Licensee.

Hazeltree shall not diminish the protections provided by the controls set forth in this Addendum and the most recently completed Audit Reports.

If Hazeltree has provided responses to Licensee’s information security or information security architecture questionnaire(s), Hazeltree will comply with Hazeltree’s information security policies, plans, procedures, standards and other information set forth or referenced in Hazeltree’s responses to such information security and information security architecture questionnaire(s) and any responses to any follow up questions related thereto provided prior or during the term of this Agreement and any such updated information provided to Licensee during the term of this Agreement. In addition, Hazeltree agrees that Licensee may periodically (no more than annually) deliver a questionnaire inquiring into Hazeltree’s data security, disaster recovery and business continuity, and regulatory compliance policies and procedures, and Hazeltree agrees to promptly and completely respond to the questionnaire.

Hazeltree shall require and ensure that any of its subcontractors, sub-processors, agents and affiliates that have access to Licensee Data are subject to, and comply with, substantially the same requirements as set forth in this Addendum.

Security Program.

Hazeltree shall maintain a comprehensive, written information security program that contains administrative, technical, organizational, and physical safeguards and security measures that are appropriate to (i) the size, scope and type of Hazeltree’s business; (ii) the amount of resources available to Hazeltree; (iii) the type of information that Hazeltree will store or process; and (iv) the need for security and confidentiality of such information.

Hazeltree shall design the security program to protect and safeguard information as set forth in any local, state or federal regulations by which Hazeltree may be regulated.

Hazeltree’s security program must adhere to standard industry practices and include at least the following:

Security Awareness and Training Program: A mandatory security awareness and training program for all members of Hazeltree’s workforce (including management), which includes (A) training on how to implement and comply with its information security program; and (B) promoting a culture of security awareness through periodic communications from senior management with employees.

Access Controls: Policies, procedures, and logical controls designed to (A) manage and monitor personnel with access to Licensee Data; (B) limit access to its information systems in which Licensee Data is housed to properly authorized persons; (C) prevent those workforce members and others who should not have access to Licensee Data or such information systems from obtaining access; (D) to detect any unauthorized use or access; and (E) remove access in a timely basis in the event of a change in job responsibilities or job status.

Physical and Environmental Security: Controls that provide reasonable assurance that access to physical servers at the production data center is limited to properly authorized individuals and that environmental controls are established to detect, prevent and control destruction due to environmental extremes, including:

Logging and monitoring of unauthorized access attempts to the data center by the data center security personnel;

Camera surveillance systems at critical internal and external entry points to the data center;

Systems that monitor and control the air temperature and humidity at appropriate levels for the computing equipment; and

Uninterruptible Power Supply (“UPS”) modules and backup generators that provide back-up power in the event of an electrical failure.

Security Incident Procedures: A security incident response plan that includes procedures to be followed in the event of any security breach of Licensee Data or any security breach of any application or system directly associated with the accessing, processing, storage, communication or transmission of Licensee Data, including:

Roles and responsibilities: Formation of an internal incident response team with a response leader;

Investigation: Assessing the risk the incident poses and determining who may be affected;

Communication: Internal reporting as well as a notification process in the event of unauthorized disclosure of Licensee Data;

Recordkeeping: Keeping a record of what was done and by whom to help in later analysis and possible legal action; and

Audit: Conducting and documenting root cause analysis and remediation plan.

Contingency Planning/Disaster Recovery: Policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, pandemic flu, and natural disaster) that could damage Licensee Data or production systems that contain Licensee Data, including:

Data Backups: A policy for performing periodic backups of production file systems and databases, which includes regular incremental backups, or an equivalent.

Disaster Recovery: A formal disaster recovery plan for the production data center, including requirements for the disaster plan to be tested on a regular basis (but in no event less than once per calendar year) and a documented executive summary of the disaster recovery testing, which is available upon request to Licensee.

Business Continuity Plan: A formal process to address the framework by which an unplanned event might be managed in order to minimize the loss of vital resources.

Audit Controls: Hardware, software, or procedural mechanisms that record and examine activity in information systems that contain or use electronic information, including appropriate logs and reports concerning these security requirements.

Storage and Transmission Security: Technical security measures to guard against unauthorized access to Licensee Data that is being transmitted over a public electronic communications network through the SFTP procedures or stored electronically through TLS. Such measures include requiring encryption of any Licensee Data stored on servers, desktops, laptops or other removable storage devices, including all backup copies.

Secure Disposal: Policies and procedures regarding the disposal of tangible property containing Licensee Data, taking into account available technology, so that Licensee Data cannot be practicably read or reconstructed.

Assigned Security Responsibility: Assigning responsibility for the development, implementation, and maintenance of its information security program, including:

Designating a security official with overall responsibility;

Defining security roles and responsibilities for individuals with security responsibilities; and

Designating a security council consisting of cross-functional management representatives to meet on a regular basis.

Testing: Regularly (but in no event less than once per calendar year and after any material changes or upgrades are made) testing of the key controls, systems and procedures of its information security program to validate that they are properly implemented and effective in addressing the threats and risks identified, including internal risk assessments. Hazeltree shall promptly remediate any critical or high-risk issues identified during any such testing.

Monitoring: Monitoring the network and production systems, including error logs on servers, disks, and security logs for any potential problems, including:

Reviewing changes affecting systems handling authentication, authorization, and auditing;

Reviewing privileged access to Hazeltree production systems; and

Engaging third parties to perform network vulnerability assessments and application penetration testing on a regular basis.

Change and Configuration Management: Maintaining policies and procedures for managing changes to production systems, applications, and databases, including:

A process for documenting, testing and approving the promotion of changes into production;

A security patching process that requires patching systems in a timely manner based on a risk analysis; and

A process for Hazeltree to utilize a third party to conduct web application level security assessments.

Program Adjustments: Monitoring, evaluating, and adjusting, as appropriate, the security program in light of (A) any relevant changes in technology and any internal or external threats to Hazeltree or the Licensee Data; (B) cybersecurity regulations applicable to Hazeltree; and (C) Hazeltree’s own changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to information systems.

If Hazeltree accesses Licensee’s network, Hazeltree will apply the “principle of least privilege” in requesting access to Licensee’s network, and Hazeltree will implement appropriate monitoring controls to limit access to Licensee’s network solely to those of Hazeltree personnel for whom such access is needed to support the SaaS Services. Hazeltree shall ensure that access to Licensee’s network by Hazeltree’s employees is only provided, and remains at all times in compliance with, Licensee’s approved methods.

Inspections/Reviews/Remediation.

Hazeltree will provide to Licensee, Licensee’s auditors (including internal audit staff and external auditors) and regulators or other law enforcement agents access at all reasonable times, after providing Hazeltree with at least thirty (30) days advance notice (except in the event of audits or investigations by regulators or other law enforcement agents, or investigations of reasonable suspicion of misappropriation, fraud or business irregularities of a potentially criminal nature, or relating to Licensee data protection requirements as required by law), to any Hazeltree office at which either Hazeltree or any of Hazeltree’s personnel are providing the SaaS Services (including Hazeltree’s systems) and to data and records relating to the SaaS Services or a Cybersecurity Event for the purpose of performing audits designed to enable Licensee or regulators or other law enforcement agents to confirm that Hazeltree is meeting all applicable information security requirements and regulatory and other legal requirements. Where Hazeltree uses any multi-tenant cloud or “-as-a-Service” provider (such as Amazon, Google, or Azure) (“Cloud Providers”) as part of Hazeltree’s systems, and such Cloud Providers reasonably restrict access for Licensee audits, then, as an alternative, Hazeltree will cooperate with Licensee and the Cloud Providers to demonstrate to Licensee (or its agents or regulators) Hazeltree’s environment and operations at the Cloud Provider in order for Licensee to ensure that such Cloud Provider’s security configurations and controls (including policies and procedures) substantially conform to the requirements of this Agreement and are at least as strong as standard industry practices for such SaaS Services.

If Licensee notifies Hazeltree of any deficiencies or noncompliance with this Section 3 (Inspections/Reviews/Remediation) or reasonably believes that Hazeltree’s reports, described above, do not address any requirements set out in this Addendum or if Licensee identifies any issues based on Hazeltree’s responses to Licensee questionnaires, Hazeltree will, without undue delay commensurate with the risk and nature of the Licensee Data, remediate such issues, deficiencies, or noncompliance. If Hazeltree does not remedy any such issues, deficiencies, or noncompliance to Licensee’s reasonable satisfaction within thirty (30) days, Licensee has the right to terminate this Agreement upon written notice to Hazeltree, in which case Hazeltree shall refund to Licensee the pro rata unused portion of any prepaid fees. Licensee will have the right to conduct follow-up audits and demonstrations, as applicable, to confirm remediation.

Breach Notification and Remediation Requirements[DP2] (#_msocom_2) .

If Hazeltree learns or has reason to believe that there has been (i) unauthorized or unlawful access to or use of the Licensee Data; or (ii) accidental loss or destruction of, damage to, or disclosure, modification, or deletion of the Licensee Data (each, a “Cybersecurity Event”), Hazeltree will promptly, but in no event later than forty-eight (48) hours from becoming aware of the Cybersecurity Event, provide notice of the Cybersecurity Event to Licensee. Such notice must be in writing or sent to an email address approved in writing by Licensee and must include all known material details of the Cybersecurity Event.

Hazeltree will (i) promptly use commercially reasonable efforts to mitigate the effects of a Cybersecurity Event on Licensee, including preventing, or preventing any further, destruction of, damage to, or disclosure, modification, or deletion of the Licensee Data; and (ii) provide timely updates to Licensee, or promptly upon request, relating to the investigation and resolution of the Cybersecurity Event.

Hosting is addressed below. Isn’t Hazeltree’s sub-processor (e.g., AWS) doing this?

This should already be addressed in the DPA or Agreement.