Information, Security and Data Privacy and Protection Policy

Information Security: PPI agrees that it will strictly protect and strictly maintain the security of all information provided by the Client. An Information Security Incident (“ISI”) is a situation in which PPI confirms or reasonably suspects that an unauthorized party has accessed or may have the ability to access any such information that PPI has in its possession or can access. PPI agrees to, on discovering an ISI, alert the Client immediately, and in no instance more than twenty-four (24) hours following its discovery of the ISI, via an e-mail to Client. PPI agrees that in the event of an ISI, PPI will (A) coordinate with the Client to take all necessary steps to minimize the impact of the ISI on the Client; (B) cooperate with the Client in handling the matter, including, but not limited to, assisting with any investigation, providing the Client with access to appropriate facilities, systems, and people, and making all relevant records, files, data, and other material required to comply with applicable laws and regulations; and (C) promptly using its best efforts to prevent a recurrence of any such ISI. PPI additionally agrees that it shall not inform any third party of any ISI without first obtaining the Client’s written consent and approval of such notice.

Data Privacy and Protection: PPI understands that in connection with its engagement under this Agreement, PPI may receive or be exposed to Personal Data, which means any information that alone or in combination with other information held by or likely to come into the possession of PPI allows the identification of an individual (whether identified by name or other identifier), or as defined by “Data Protection Laws” including Regulation (EU) 2016/679 (EU General Data Protection Regulation or “GDPR”) or any similar data privacy laws in any jurisdiction. PPI and the Client acknowledge and agree that, in the context of this Agreement, each is and will each be an independent controller in respect to any Personal Data subject to any applicable Data Protection Laws. PPI and the Client will each comply with its obligations under the Data Protection Laws at all times in relation to the Personal Data. PPI shall provide the data subjects of the Personal Data with a copy of its privacy notice regarding the processing of Personal Data upon request.