Laserfiche WebLink
aANe, <br />software <br />Avolve or the Avolve SAAS Solution, Avolve, as its sole obligation and liability and as Customer's sole <br />remedy, will use commercially reasonable efforts to restore Customer Data from Avolve's most current <br />backup of Customer Data. <br />M. Ownership. Customer acknowledges and agrees that Avolve owns all right, title, and interest in and to <br />all intellectual property rights (including all derivatives or improvements thereof) in the Avolve SAAS <br />Solution and any suggestions, enhancements requests, feedback, recommendations or other <br />information provided by Customer or any of its Users related to the Avolve SAAS Solution. Customer's <br />use rights to the Avolve SAAS Solution and the related materials supplied by Avolve pursuant to this <br />Agreement are strictly limited to the right to use the proprietary rights in accordance with the terms of <br />this Agreement. No right of ownership, expressed or implied, is granted under this Agreement. <br />2. Security. The security, privacy and data protection commitments set forth in this Agreement only apply to <br />products and services provided by Avolve directly to Customer and do not include any products or services <br />resold by Avolve hereunder, including any hosting services provided by Microsoft Corporation pursuant to the <br />Customer's Microsoft Customer Agreement. <br />a. Security Program. Avolve has implemented and maintains an information security program that <br />incorporates administrative, technical, and physical safeguards designed to protect the security, <br />confidentiality, and integrity of the Customer Data provided by Customer and its Users to Avolve in <br />accordance with this Agreement. <br />b. Annual Audit. Avolve will use commercially reasonable efforts to conduct an annual security audit of <br />Avolve using an independent third party selected by Avolve. Upon the Customer's written request, a <br />copy of the final report from any such audit shall be promptly made available to the Customer for <br />inspection (but not copying). The Customer agrees that any such reports or other information provided <br />to Customer concerning any audit shall be the Confidential Information of Avolve. <br />C. Security Breach. Avolve will notify Customer promptly and in no event later than one (1) business day <br />following Avolve's discovery of a Data Security Breach (defined below) and shall (i) undertake a <br />reasonable investigation of the reasons for and the circumstances surrounding such Data Security <br />Breach and (ii) reasonably cooperate with Customer in connection with such investigation, including <br />by providing Customer with an initial summary of the results of Avolve's investigation as soon as <br />possible, but in all cases within two (2) business days after the date Avolve discovered or reasonably <br />suspected a Data Security Breach, and then regular updates on the investigation as it progresses; (iii) <br />not make any public announcements relating to such Data Security Breach without Customer's prior <br />written approval, which shall not be unreasonably withheld; (iv) use commercially reasonable efforts <br />to take all necessary and appropriate corrective action reasonably possible on Avolve's part designed <br />to prevent a recurrence of such Data Security Breach; and (v) collect and preserve evidence concerning <br />the discovery, cause, vulnerability, remedial actions and impact related to such Data Security Breach, <br />which shall meet reasonable expectations of forensic admissibility. In the event any Data Security <br />Breach is caused by Avolve, Customer shall have, in addition to all other rights and remedies available <br />under this Agreement, law and equity, the right to immediately terminate the Agreement. For <br />purposes of this Agreement, the term "Data Security Breach" shall mean any of the following occurring <br />in connection with Customer Data in connection with Customer's and its Users' authorized use of the <br />Avolve SAAS Solution: (a) the loss or misuse of Customer Data; and (b) disclosure to, or acquisition, <br />access or use by, any person not authorized to receive Customer Data, other than in circumstances in <br />which the disclosure, acquisition, access or use is made in good faith and within the course and scope <br />of the employment with Avolve or other professional relationship with Avolve and does not result in <br />any further unauthorized disclosure, acquisition, access or use of Customer Data. <br />#39664v202092017 Page 8 of 30 <br />