Laserfiche WebLink
sricnw~ <br />SUBSCRIPTION SERVICE GU DE EFFECTIVE DATE: NOVEMBER 12, 2014 <br />4. DATA PROTECTION AND SERVICE CONTINUITY <br />4.1. Data Centers; Data Backup. ServiceNow shall host Customer's instances in primary and <br />secondary SSAE 16 Type II or ISO 27001 certified (or equivalent) data centers in the geographic regions <br />specified on the Order Form for the Subscription Term. Each data center includes full redundancy (N+1) and fault <br />tolerant infrastructure for electrical, cooling and network systems. The deployed servers are enterprise scale <br />servers with redundant power to ensure maximum uptime and service availability. The production database <br />servers are replicated in near real time to a mirrored data center in a different geographic region. Each customer <br />instance is supported by a network configuration with multiple connections to the Internet. ServiceNow backs up <br />all Customer Data in accordance with ServiceNow's standard operating procedure. <br />4.2. Personnel. In the event of an emergency that renders the customer support telephone system <br />unavailable, all calls are routed to an answering service that will transfer to a ServiceNow telephone support <br />representative, geographically located to ensure business continuity for support operations. <br />5. INCIDENT MANAGEMENT AND BREACH NOTIFICATION <br />5.1. Incident Monitoring and Management. ServiceNow shall monitor, analyze and respond to <br />security incidents in a timely manner in accordance with ServiceNow's standard operating procedure. Depending <br />on the nature of the incident, ServiceNow security group will escalate and engage response teams necessary to <br />address an incident. <br />5.2. Breach Notification. Unless notification is delayed by the actions or demands of a law <br />enforcement agency, ServiceNow shall report to Customer the unauthorized acquisition, access, use, disclosure <br />or destruction of Customer Data (a "Breach") promptly following determination by ServiceNow that a Breach <br />occurred. The initial report shall be made to Customer security contact(s) designated in ServiceNow's customer <br />support portal. ServiceNow shall take reasonable measures to promptly mitigate the cause of the Breach and <br />shall take reasonable corrective measures to prevent future Breaches. As information is collected or otherwise <br />becomes available to ServiceNow and unless prohibited by law, ServiceNow shall provide information regarding <br />the nature and consequences of the Breach that are reasonably requested to allow Customer to notify affected <br />individuals, government agencies and/or credit bureaus. Customer is solely responsible for determining whether <br />to notify impacted Data Subjects (defined in 6.1 below) and for providing such notice, and for determining if <br />regulatory bodies or enforcement commissions applicable to Customer or Customer Data need to be notified of <br />a Breach. <br />5.3. Customer Cooperation. Customer agrees to cooperate with ServiceNow in maintaining <br />accurate contact information in the customer support portal and by providing any information that is reasonably <br />requested to resolve any security incident, identify its root cause(s) and prevent a recurrence. <br />6. DATA PROCESSING GUIDELINES; COMPLIANCE WITH LAWS <br />6.1. Customer as Data Controller. Customer acknowledges that in relation to Personal Data <br />supplied and/or processed under the Agreement it acts as Controller and it warrants that it will duly observe all of <br />its obligations under all applicable laws and regulations of the European Union, the European Economic Area and <br />their member states regarding the processing of Personal Data (collectively referred to as "Data Protection Laws") <br />including, without limitation, obtaining and maintaining all necessary notifications and obtaining and maintaining <br />all necessary Data Subject Consents. Customer shall (i) have sole responsibility for the accuracy, quality, <br />integrity, legality and reliability of Personal Data and of the means by which it acquired Personal Data, (ii) ensure <br />that data processing instructions given to ServiceNow comply with applicable Data Protection Laws, and (iii) <br />comply with all applicable Data Protection Laws in collecting, compiling, storing, accessing and using Personal <br />Data in connection with the Subscription Service. For the purposes of this Data Security Guide, "Personal Data", <br />"Controller", "Data Subject" and "Data Subject Consent" shall have the meaning given to these terms in Directive <br />95/46/EC. For clarity, "process" or "processing" means any operation or set of operations performed upon <br />Customer Data. <br />6.2. ServiceNow as Data Processor. ServiceNow shall process or otherwise use Personal Data <br />(including possible onward transfers) on behalf of Customer solely for the purpose of providing the services <br />SERVICENOw CONFIDENTIAL Page 9 (version 11/12/2014) <br />