Laserfiche WebLink
technologies <br />access and use the SaaS solely for the benefit of Ordering Activity's internal business purposes in accordance with the provisions of <br />this Agreement. <br />3.3. Ordering Activity acknowledges and agrees that in order for CA to effectively provide SaaS, Ordering Activity may be required to <br />provide necessary information and shall not delay, prevent or interfere with CA's provision of SaaS. <br />4. FEES & RENEWAL <br />4.1. Ordering Activity may access SaaS for solely the number and type of Users specified in the Authorized CA Partner's order with CA. <br />Additional Users, or an additional SaaS offering, if available, shall require Ordering Activity to procure with CA or an Authorized CA <br />Partner (whether directly or through a Prime Contractor) for such users or offering. Unless otherwise agreed by CA, (i) additional <br />Users may be purchased only in increments of 50 Users; and (ii) such additional User subscriptions shall be coterminous with the <br />expiration of the Subscription Term. <br />4.2. CA may with notice prior to any renewal, replace the Ordering Activity ordered SaaS with replacement, underlying software that is <br />generally available to customers with alternative, materially similar, functionality. <br />4.3. The fees for SaaS subscription are not contingent upon the delivery of any future functionality or features of the CASoftware. <br />5. ORDERING ACTIVITY DATA <br />5.1. Ordering Activity exclusively owns all rights, title and interest in and to all Ordering Activity Data. Ordering Activity Data shall be <br />considered to be Confidential Information under the Agreement. CA shall not access Ordering Activity's User accounts, or Ordering <br />Activity Data, except (i) in the course of data center business operations if required, (ii) in response to SaaS or technical issues or (iii) <br />at Ordering Activity's specific request as reasonably required in the provision of SaaS. CA will segregate Ordering Activity's Data from <br />other customers' data. <br />5.2. CA operates and maintains a disaster recovery procedure. In case of a Force Majeure Event, Ordering Activity acknowledges and <br />agrees that Ordering Activity Data may not be recoverable and accepts responsibility for re-entry of such data. <br />5.3. Ordering Activity Data will be returned to the Ordering Activity at the end of the Subscription Term or at the termination of the SaaS <br />subscription in the manner described in the SaaS Documentation. <br />6. SECURITY <br />6.1. CA shall adhere to SAS 70 Type II audit compliance criteria and data security procedures which meet ISO 27001 status during the <br />Subscription Term. <br />6.2. CA shall comply with CA's security policy and procedures, which policies and procedures are designed to provide and maintain <br />commercially reasonable safeguards against the destruction, loss or alteration of, or unauthorized access to or use of the Ordering <br />Activity Data in CA's possession or control and which safeguards are, at a minimum, no less rigorous than those maintained by CA for <br />its own information of a similar nature. <br />6.3. Ordering Activity Data shall be stored pursuant to CA's data security procedures, which shall be provided to Ordering Activity upon <br />request. Except as required herein, CA will not be responsible for any unauthorized access to, or alteration, theft or destruction of <br />Ordering Activity Data, unless caused as a result of CA's negligence or intentional misconduct, in which case restoring or recovery of <br />Ordering Activity Data shall be limited to the most recent back-up of Ordering Activity Data. CA is not responsible for loss of Ordering <br />Activity Data arising from Ordering Activity's: (i) transmission of data in contravention of the User Guide; or (ii) failure to act on any <br />CA provided communication. <br />6.4. CA shall comply with the applicable EU member states' implementation of the Directive 95/46/EC ("Directive") governing the <br />processing of personal data as defined specifically in the Directive and CA, Inc. is Safe Harbour certified. <br />6.5. Ordering Activity or an independent third party may audit CA's operations within the applicable data center to verify CA's compliance <br />with the security and technical provisions defined in this Module. The audit may take place, no more than once annually, upon thirty <br />(30) days prior written notice subject to Ordering Activity or its independent third party having executed a CA confidentiality <br />agreement and stating the purpose and scope of the request. Such audit shall be conducted during normal business hours in a <br />manner that does not disrupt business operations. <br />7. INITIATION AND SUPPORT PROCESSES <br />7.1. The following processes apply to the SaaS: <br />CA will send an email to Ordering Activity's technical contact identified in the Authorized CA Partner's order with CA setting out <br />the SaaS URL(s) and other information necessary for initial use of the SaaS. Ordering Activity shall provide information as <br />requested within 7 days of receiving the email. <br />Version PS 1.0 Page 7 of 38 7/23/2014 10:36 AM <br />