This Data Processing Addendum (“DPA”) is entered into by and between ORM Technologies, LLC (“ORM”) and the customer that is a party to the applicable Agreement (“Customer”). ORM and Customer are each a “Party” and together the “Parties.”
This DPA forms part of the applicable Master Services Agreement, Order Form, Statement of Work, or other written agreement governing Customer’s use of the Services (collectively, the “Agreement”) when this DPA is signed by the Parties, referenced in an Order Form, or otherwise incorporated into the Agreement in writing.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Scope and Order of Precedence
This DPA applies to ORM’s Processing of Customer Personal Data on behalf of Customer in connection with the Services.
If this DPA conflicts with the Agreement regarding ORM’s Processing of Customer Personal Data, this DPA controls only to the extent required by Applicable Data Protection Law. In all other respects, the Agreement controls and remains unchanged.
Nothing in this DPA:
- Expands ORM’s indemnification obligations;
- Creates separate or cumulative liability;
- Creates service levels not stated in the Agreement;
- Requires ORM to provide backup, archival, or recovery services beyond those stated in the Agreement; or
- Limits ORM’s rights concerning aggregated or de-identified data under the Agreement.
2. Definitions
For purposes of this DPA:
2.1 Applicable Data Protection Law
“Applicable Data Protection Law” means privacy, data protection, and data security laws applicable to ORM’s Processing of Customer Personal Data under the Agreement.
Applicable Data Protection Law may include, where applicable:
- Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”);
- The United Kingdom General Data Protection Regulation and Data Protection Act 2018 (“UK Data Protection Law”);
- The Swiss Federal Act on Data Protection;
- Applicable United States state privacy laws; and
- Laws that amend, replace, or supersede the foregoing.
2.2 Controller
“Controller” means the entity that determines the purposes and means of Processing Personal Data. “Controller” includes equivalent terms such as “business” where applicable under Applicable Data Protection Law.
2.3 Customer Personal Data
“Customer Personal Data” means Personal Data that ORM Processes on behalf of Customer in connection with the Services, including Personal Data received from systems, services, platforms, applications, or integrations authorized by Customer or its Users.
Customer Personal Data does not include information for which ORM determines the purposes and means of Processing independently of Customer, including information ORM processes for its own account administration, billing, security, legal compliance, or business operations.
2.4 Data Subject
“Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates. “Data Subject” includes equivalent terms such as “consumer” where applicable under Applicable Data Protection Law.
2.5 Personal Data
“Personal Data” means information relating or reasonably capable of being linked to an identified or identifiable individual or household and includes equivalent terms such as “personal information” where applicable under Applicable Data Protection Law.
2.6 Process or Processing
“Process,” “Processed,” or “Processing” means any operation performed on Personal Data, including collecting, accessing, importing, recording, organizing, storing, adapting, retrieving, analyzing, using, transmitting, making available, restricting, deleting, or destroying Personal Data.
2.7 Processor
“Processor” means an entity that Processes Personal Data on behalf of a Controller. “Processor” includes equivalent terms such as “service provider,” “contractor,” or “subprocessor” where applicable under Applicable Data Protection Law.
2.8 Security Incident
“Security Incident” means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by ORM.
Security Incident does not include:
- Unsuccessful attempts or activities that do not compromise Customer Personal Data;
- Routine scans, probes, unsuccessful login attempts, denial-of-service attempts, or similar events;
- Incidents caused by Customer, its Users, or a Customer-selected connected service; or
- Events affecting information that is encrypted, de-identified, or otherwise rendered unintelligible, unless Applicable Data Protection Law provides otherwise.
2.9 Subprocessor
“Subprocessor” means a third party engaged by ORM to Process Customer Personal Data on behalf of Customer.
A service, platform, application, or API selected or authorized by Customer is not an ORM Subprocessor solely because ORM receives data from or transmits data to that service at Customer’s direction.
3. Roles of the Parties
3.1 Appointment
Customer appoints ORM to Process Customer Personal Data on Customer’s behalf in connection with the Services.
Customer is the Controller and ORM is the Processor of Customer Personal Data.
If Customer acts as a Processor on behalf of another Controller, Customer appoints ORM as a Subprocessor. Customer is responsible for obtaining any authorization required from the applicable Controller.
3.2 Customer Instructions
ORM will Process Customer Personal Data:
- To provide, operate, maintain, secure, support, develop, and improve the Services, including their functionality, reliability, performance, and security;
- To perform the Agreement and applicable Order Forms or Statements of Work;
- To establish, maintain, and support Customer-authorized integrations;
- To authenticate Users and administer access;
- To import, store, organize, analyze, display, report on, synchronize, or otherwise Process Customer Personal Data through the Services;
- To produce analytics, models, forecasts, recommendations, reports, and other Outputs;
- To identify, associate, and analyze marketing, sales, engagement, account, opportunity, and outcome information at the individual, account, campaign, or organizational level;
- To respond to support requests;
- To prevent or address fraud, misuse, security threats, or technical issues;
- As otherwise documented by Customer; and
- As required by applicable law.
The Agreement, Order Forms, Statements of Work, Customer’s configuration and use of the Services, Customer-authorized integrations, support requests, and other written directions from Customer constitute Customer’s documented instructions.
ORM may suspend or decline an instruction that ORM reasonably believes violates Applicable Data Protection Law, the Agreement, or applicable third-party provider requirements.
3.3 ORM’s Independent Processing
Nothing in this DPA prevents ORM from Processing information as an independent Controller where ORM determines the purposes and means of Processing, including for:
- Account administration;
- Billing and financial management;
- Business communications;
- Service security and fraud prevention;
- Compliance with law;
- Establishment, exercise, or defense of legal claims; and
- Other legitimate business operations described in ORM’s Privacy Policy.
ORM’s independent Processing is governed by ORM’s Privacy Policy and Applicable Data Protection Law rather than this DPA.
3.4 Aggregated and De-Identified Data
Nothing in this DPA restricts ORM’s rights under the Agreement to create, use, reproduce, disclose, or distribute aggregated or de-identified data.
ORM will not attempt to re-identify information that has been de-identified, except as permitted by Applicable Data Protection Law to test whether its de-identification processes are effective.
4. Customer Responsibilities
Customer is responsible for:
- The lawfulness, accuracy, quality, and integrity of Customer Personal Data;
- Determining the purposes and means of Processing;
- Providing required privacy notices;
- Obtaining required permissions, authorizations, and consents;
- Establishing a lawful basis for Processing Customer Personal Data;
- Ensuring that its instructions to ORM comply with Applicable Data Protection Law;
- Configuring the Services and connected services appropriately;
- Selecting and authorizing integrations and access permissions;
- Managing its Users, credentials, roles, and permissions;
- Responding to Data Subject requests as Controller;
- Determining whether the Services are appropriate for Customer’s intended use;
- Determining whether Customer’s use of the Services involves profiling, automated decision-making, targeted advertising, or other regulated Processing and implementing any notices, lawful bases, consents, safeguards, human review, and rights required by Applicable Data Protection Law; and
- Complying with laws applicable to Customer’s collection, use, and disclosure of Customer Personal Data.
Customer represents and warrants that:
- It has all rights and authority necessary for ORM to Process Customer Personal Data as contemplated by the Agreement and this DPA;
- Its instructions will not cause ORM to violate Applicable Data Protection Law; and
- It will not provide or direct ORM to Process prohibited or highly sensitive information unless the Parties expressly agree in writing to such Processing.
Unless expressly agreed in an Order Form or Statement of Work, Customer will not submit:
- Protected health information regulated by HIPAA;
- Payment card information subject to PCI DSS;
- Government-issued identification numbers;
- Biometric identifiers used for identification;
- Precise geolocation information;
- Information concerning children under 13;
- Special categories of Personal Data under Article 9 of the GDPR; or
- Criminal conviction or offense information.
5. ORM Obligations
5.1 Compliance
ORM will comply with Applicable Data Protection Law applicable to ORM’s Processing of Customer Personal Data as a Processor.
5.2 Confidentiality
ORM will ensure that persons authorized to Process Customer Personal Data:
- Are subject to confidentiality obligations;
- Receive appropriate privacy and security training; and
- Access Customer Personal Data only as necessary to perform their responsibilities.
5.3 Required Processing
If ORM is required by law to Process Customer Personal Data other than as instructed by Customer, ORM will notify Customer before the Processing unless the law prohibits notice.
5.4 Requests and Communications
If ORM receives a request from a Data Subject concerning Customer Personal Data, ORM may direct the Data Subject to Customer.
ORM will not independently respond to the substantive request unless:
- Customer instructs ORM to respond;
- Applicable Data Protection Law requires ORM to respond; or
- ORM is acting as an independent Controller for the relevant information.
6. Security
6.1 Security Measures
ORM will maintain reasonable administrative, technical, physical, and organizational safeguards designed to protect Customer Personal Data against unauthorized access, use, alteration, disclosure, or destruction.
ORM’s safeguards will take into account:
- The nature, scope, context, and purposes of Processing;
- The sensitivity of Customer Personal Data;
- The risks presented by the Processing;
- The state of the art; and
- The costs of implementation.
The general categories of safeguards maintained by ORM are described in Schedule 2.
6.2 Changes to Safeguards
ORM may modify its safeguards from time to time, provided that the modifications do not materially reduce the overall level of protection for Customer Personal Data during the applicable subscription term.
6.3 Customer Security Responsibilities
Customer is responsible for:
- Securing its systems, accounts, devices, credentials, and networks;
- Properly configuring access rights and integrations;
- Promptly removing access for unauthorized or former Users;
- Maintaining backup or archival copies as required by the Agreement; and
- Promptly notifying ORM of suspected unauthorized access or misuse.
7. Security Incidents
7.1 Notice
ORM will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data.
Notice will be sent to the contact information maintained by ORM for Customer unless Customer designates a different security contact in writing.
7.2 Information and Cooperation
Taking into account the nature of the Security Incident and information reasonably available to ORM, ORM will provide information reasonably necessary to assist Customer with its obligations under Applicable Data Protection Law.
ORM may provide information in phases as it becomes available.
7.3 Response
ORM will take reasonable steps to investigate, contain, mitigate, and remediate a Security Incident.
ORM’s notice or response to a Security Incident will not be construed as an admission of fault or liability.
7.4 Customer Obligations
Customer is responsible for determining whether notification to a regulator, Data Subject, or other party is required and for providing any required notification, unless Applicable Data Protection Law expressly assigns that responsibility to ORM.
8. Subprocessors
8.1 General Authorization
Customer grants ORM general authorization to engage Subprocessors to Process Customer Personal Data.
ORM remains responsible for its Subprocessors’ performance of their data protection obligations to the extent required by Applicable Data Protection Law.
8.2 Subprocessor Terms
ORM will ensure that each Subprocessor is subject to a written agreement, including applicable online or incorporated terms, that includes the data protection obligations required by Applicable Data Protection Law for the Processing performed by that Subprocessor.
8.3 Subprocessor Information
ORM will make its then-current list of Subprocessors available to Customer upon written request or through another method designated by ORM.
8.4 Changes and Objections
ORM may add or replace Subprocessors.
Where required by Applicable Data Protection Law, ORM will provide advance notice of a new Subprocessor through email, a webpage, the Services, or another reasonable method.
Customer may object to a new Subprocessor only:
- On reasonable and documented grounds directly relating to the protection of Customer Personal Data; and
- By providing written notice within fourteen days after ORM’s notice.
The Parties will work in good faith to address a valid objection.
ORM may, in its discretion:
- Elect not to use the Subprocessor for Customer;
- Propose a commercially reasonable alternative;
- Modify the affected Services; or
- Permit Customer to terminate only the portion of the affected Services that cannot reasonably be provided without the Subprocessor.
If Customer terminates affected Services under this Section, termination will be Customer’s sole and exclusive remedy, and any refund will be determined under the Agreement.
8.5 Emergency Changes
ORM may add or replace a Subprocessor without advance notice where reasonably necessary to address an emergency, security risk, service interruption, legal requirement, or event outside ORM’s reasonable control.
ORM will provide notice as soon as reasonably practicable where required by Applicable Data Protection Law.
9. Assistance to Customer
9.1 Data Subject Requests
Taking into account the nature of ORM’s Processing and the functionality of the Services, ORM will provide reasonable assistance to Customer with Data Subject requests to the extent required by Applicable Data Protection Law.
Where available, Customer will use the functionality of the Services to access, correct, export, restrict, or delete Customer Personal Data before requesting assistance from ORM.
9.2 Assessments and Consultations
Taking into account the nature of Processing and information available to ORM, ORM will provide reasonable assistance with:
- Data protection impact assessments;
- Prior consultations with regulators; and
- Customer’s assessment of ORM’s Processing activities,
in each case only to the extent required by Applicable Data Protection Law.
9.3 Government and Regulatory Requests
Unless prohibited by law, ORM will notify Customer if ORM receives a legally binding request from a government authority specifically seeking Customer Personal Data.
ORM may:
- Review the request for legal validity;
- Challenge the request where ORM reasonably determines a challenge is appropriate;
- Seek to limit disclosure; and
- Disclose only information ORM reasonably believes it is legally required to disclose.
9.4 Costs of Assistance
ORM may charge Customer at ORM’s then-current professional services rates for assistance under this Section that requires material effort beyond the standard functionality or support included in the Services, except where the assistance is required because of ORM’s breach of this DPA.
10. Security Information and Audits
10.1 Documentation
Upon written request and subject to confidentiality obligations, ORM will make available information reasonably necessary to demonstrate ORM’s compliance with this DPA.
Such information may include, as available:
- Independent audit or certification reports;
- SOC reports;
- Security summaries;
- Relevant policies or questionnaires; and
- Written responses to reasonable security questions.
10.2 Audit Priority
Customer will first use the documentation provided by ORM to assess ORM’s compliance.
An additional audit may be requested only where:
- Required by Applicable Data Protection Law or a regulator;
- The documentation provided by ORM is reasonably insufficient; or
- Customer reasonably believes ORM has materially breached this DPA.
10.3 Audit Conditions
Any Customer audit must:
- Be conducted no more than once in any twelve-month period, except following a confirmed Security Incident or regulator requirement;
- Be limited to systems and activities relevant to Customer Personal Data;
- Occur during normal business hours;
- Be conducted on at least thirty days’ prior written notice, unless a shorter period is legally required;
- Avoid unreasonable interference with ORM’s operations;
- Be conducted by Customer or a qualified independent auditor that is not a competitor of ORM;
- Be subject to reasonable confidentiality and security requirements;
- Not provide access to other customers’ data, ORM source code, penetration-testing results, or information that would create a security risk; and
- Comply with ORM’s reasonable safety and security procedures.
10.4 Audit Costs
Customer is responsible for its audit costs and will reimburse ORM for reasonable costs incurred in supporting an audit. If a final audit report identifies a material breach of this DPA by ORM, any reimbursement of Customer’s reasonable audit costs will be subject to the limitations of liability in the Agreement.
11. Return and Deletion
11.1 During the Term
During the term, ORM will Process requests to return, export, delete, or de-identify Customer Personal Data in accordance with:
- The functionality of the Services;
- Customer’s documented instructions;
- The Agreement; and
- Applicable Data Protection Law.
11.2 Following Termination
Following expiration or termination of the applicable Services, ORM will, in accordance with the Agreement and its standard retention processes:
- Make Customer Personal Data available for retrieval where supported by the Services; and
- Delete or de-identify Customer Personal Data within a reasonable period, unless the Parties agree in writing to another action.
Deletion is subject to the exceptions in Section 11.3, including legal requirements, legal holds, security and audit needs, and routine backup and disaster-recovery systems.
11.3 Exceptions
ORM may retain Customer Personal Data:
- As required or permitted by law;
- To establish, exercise, or defend legal claims;
- To comply with legal holds;
- For fraud prevention, security, or audit purposes;
- As part of routine backup and disaster-recovery systems; or
- Where deletion is not reasonably feasible because of the manner in which the data is stored.
Any retained Customer Personal Data will remain subject to the applicable confidentiality and security obligations of this DPA and will be used only for the purpose permitting retention.
Customer Personal Data retained in backups will be deleted or overwritten through ORM’s normal backup lifecycle.
12. International Transfers
12.1 Transfer Mechanisms
Where ORM’s Processing of Customer Personal Data involves a restricted international transfer, the Parties will rely on a lawful transfer mechanism recognized under Applicable Data Protection Law.
A lawful mechanism may include:
- An adequacy decision;
- The EU Standard Contractual Clauses;
- The UK International Data Transfer Addendum or International Data Transfer Agreement;
- A certification framework applicable to ORM;
- Binding corporate rules; or
- Another legally recognized transfer mechanism.
12.2 EU Standard Contractual Clauses
Where the EU Standard Contractual Clauses are required, the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 dated June 4, 2021 (“EU SCCs”) are incorporated into this DPA by reference.
The following selections apply unless the Parties agree otherwise in writing:
- Module Two applies where Customer is a Controller and ORM is a Processor.
- Module Three applies where Customer is a Processor and ORM is a Subprocessor.
- Clause 7, the optional docking clause, applies.
- In Clause 9, Option 2, general written authorization, applies.
- The notice period for changes to Subprocessors is the period stated in Section 8 of this DPA.
- In Clause 11, the optional language does not apply.
- In Clause 17, Option 1 applies, and the governing law will be the law of Ireland unless another permitted jurisdiction is specified in the applicable Order Form.
- Under Clause 18, disputes will be resolved by the courts of Ireland unless another permitted jurisdiction is specified in the applicable Order Form.
- Annexes I through III are completed using the information in the Agreement, this DPA, and its Schedules.
Nothing in this DPA modifies the EU SCCs in a manner that conflicts with the EU SCCs.
12.3 United Kingdom Transfers
For restricted transfers subject to UK Data Protection Law, the then-current UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner is incorporated by reference and applies to the EU SCCs.
12.4 Switzerland
For transfers subject to Swiss data protection law:
- References in the EU SCCs to the GDPR will include applicable Swiss data protection law;
- References to an EU Member State will include Switzerland where appropriate;
- The competent supervisory authority will be the Swiss Federal Data Protection and Information Commissioner where applicable; and
- Data Subjects in Switzerland may exercise their rights in Switzerland.
12.5 Transfer Cooperation
The Parties will reasonably cooperate with legally required transfer assessments.
ORM may charge for assistance requiring material effort beyond standard compliance documentation, except where the assistance is required because of ORM’s breach of this DPA.
13. United States Privacy Laws
Where ORM Processes Customer Personal Data subject to an applicable United States state privacy law:
- ORM will Process Customer Personal Data only for the limited and specified purposes described in the Agreement, Customer’s documented instructions, and this DPA;
- ORM will not sell Customer Personal Data;
- ORM will not share Customer Personal Data for cross-context behavioral or targeted advertising;
- ORM will not retain, use, or disclose Customer Personal Data outside the direct business relationship between ORM and Customer, except as permitted by Applicable Data Protection Law;
- ORM will provide the same level of privacy protection required of processors, service providers, or contractors under Applicable Data Protection Law;
- ORM will notify Customer if ORM determines it can no longer meet its applicable obligations; and
- Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.
Nothing in this Section prevents ORM from:
- Engaging Subprocessors;
- Processing Customer Personal Data to provide, operate, maintain, secure, support, develop, or improve the Services, including their functionality, reliability, performance, and security;
- Processing Customer Personal Data as directed by Customer;
- Using aggregated or de-identified data as permitted by the Agreement and applicable law; or
- Processing information as an independent Controller where legally permitted.
14. Liability
All liability arising out of or relating to this DPA is subject to the limitations, exclusions, disclaimers, indemnification provisions, and allocation of risk in the Agreement.
Liability under this DPA is not separate from or cumulative with liability under the Agreement.
Nothing in this DPA:
- Expands either Party’s indemnification obligations;
- Creates additional remedies;
- Increases any liability cap;
- Excludes or limits liability that cannot lawfully be excluded or limited; or
- Limits rights granted directly to Data Subjects under the EU SCCs where those rights cannot be contractually limited.
15. Term and Termination
This DPA begins when it becomes part of the Agreement and remains in effect for as long as ORM Processes Customer Personal Data on behalf of Customer.
Termination of this DPA does not affect provisions that by their nature should survive, including provisions concerning:
- Confidentiality;
- Security;
- Retained data;
- International transfers;
- Liability; and
- Aggregated or de-identified data.
Customer may not terminate this DPA independently of the Agreement except where expressly permitted by the Agreement, this DPA, the EU SCCs, or Applicable Data Protection Law.
16. General Provisions
16.1 No Third-Party Beneficiaries
Except as expressly required by the EU SCCs or Applicable Data Protection Law, this DPA does not create rights in any person who is not a Party.
16.2 Changes Required by Law
ORM may update this DPA to reflect changes in Applicable Data Protection Law, the Services, or recognized international transfer mechanisms.
If an update materially reduces Customer’s protections for Customer Personal Data during an active subscription term, ORM will provide reasonable notice where required by Applicable Data Protection Law.
16.3 Electronic Acceptance and Counterparts
This DPA may be accepted electronically and executed in counterparts. Electronic signatures and copies have the same effect as originals.
16.4 Notices
Notices under this DPA will be provided in accordance with the notice provisions of the Agreement.
Privacy and security communications to ORM may be sent to:
ORM Technologies, LLC
Email: privacy@orm-tech.com
Schedule 1
Details of Processing
Subject Matter
ORM’s provision, operation, maintenance, security, support, development, and improvement of the Services, including their functionality, reliability, performance, and security, under the Agreement.
Duration
The term of the Agreement and any additional period during which ORM retains Customer Personal Data as permitted by the Agreement, this DPA, or Applicable Data Protection Law.
Nature and Purpose
ORM may collect, import, access, record, organize, structure, store, retrieve, consult, analyze, model, combine, display, report on, transmit, synchronize, restrict, delete, or otherwise Process Customer Personal Data to:
- Provide and support the Services;
- Connect to Customer-authorized systems and integrations;
- Produce analytics, models, forecasts, recommendations, reports, and Outputs;
- Associate marketing, sales, and engagement activity with specific individuals, accounts, opportunities, and business outcomes to provide attribution, analytics, forecasting, reporting, and related Services;
- Secure and maintain the Services;
- Respond to support requests;
- Comply with Customer instructions; and
- Perform the Agreement.
Categories of Data Subjects
Depending on Customer’s use of the Services, Data Subjects may include:
- Customer personnel and Users;
- Customer’s current and prospective customers;
- Customer’s vendors, partners, and representatives;
- Sales and marketing contacts;
- End users of Customer’s products or services; and
- Other individuals whose Personal Data Customer submits or makes available to the Services.
Categories of Customer Personal Data
Depending on Customer’s use of the Services, Customer Personal Data may include:
- Names and business contact details;
- Account and organization information;
- User identifiers, roles, and permissions;
- CRM, sales, marketing, advertising, campaign, pipeline, and opportunity information;
- Individual-level marketing engagement and attribution information, including marketing touches, campaign responses, website or content interactions, event participation, communication activity, and associations between individuals, accounts, opportunities, pipeline, and business outcomes;
- Customer, prospect, lead, and account records;
- Product usage and activity information;
- Communications and interaction records;
- Business financial and transaction information, including opportunity values, contract values, revenue, bookings, and related commercial information, excluding regulated payment card data unless expressly agreed;
- Information received through Customer-authorized integrations; and
- Other Personal Data submitted or made available by Customer.
Sensitive Data
The Services are not designed for highly sensitive or regulated Personal Data unless expressly agreed in writing.
Customer is responsible for ensuring that it does not submit prohibited or sensitive data except as authorized under the Agreement.
Processing Frequency
Continuous or as initiated by Customer, its Users, connected services, or the configuration of the Services.
Return and Deletion
As described in Section 11 of this DPA and the Agreement.
Schedule 2
General Security Measures
ORM maintains safeguards appropriate to the nature of the Services and Customer Personal Data. These safeguards may include, as appropriate:
Access Control
- Role-based or need-based access;
- User authentication;
- Privileged-access restrictions;
- Access review and removal procedures; and
- Password and credential controls.
Data Protection
- Encryption in transit;
- Encryption at rest where appropriate;
- Logical separation of customer information;
- Secure data-transfer methods; and
- Data-retention and disposal procedures.
System and Network Security
- Firewalls and network controls;
- Logging and monitoring;
- Vulnerability management;
- Malware protection;
- Patch and configuration management; and
- Security testing.
Development and Change Management
- Secure development practices;
- Code review and testing;
- Change-management procedures; and
- Separation of development and production environments where appropriate.
Personnel Security
- Confidentiality obligations;
- Security and privacy awareness training;
- Access based on job responsibilities; and
- Personnel offboarding procedures.
Incident Response
- Incident identification and escalation procedures;
- Investigation and containment;
- Remediation and recovery; and
- Customer notification procedures consistent with this DPA.
Business Continuity
- Backup and recovery procedures;
- Disaster-recovery planning;
- System resilience measures; and
- Periodic testing where appropriate.
Vendor Management
- Risk-based vendor review;
- Contractual confidentiality and security obligations;
- Subprocessor management; and
- Periodic review where appropriate.
ORM may update these measures provided that the overall level of protection is not materially reduced during the applicable subscription term.