TERMS & CONDITIONS
Effective Date: August 6, 2026 (Prior version archived here.)
These Terms and Conditions (collectively, with all addenda hereto, the “Terms”) are entered into effective as of the Effective Date, by and between NowSecure, Inc., (“NowSecure”), and the Customer entity identified in the applicable Order Form (“Customer”). In consideration of the mutual benefits described below and for other good and valuable consideration, the sufficiency of which is hereby acknowledged, the parties agree as follows:
1. DEFINITIONS
“Account” means the account Customer establishes with NowSecure when first accessing the Services.
“Affiliate” means any entity that directly or indirectly Controls, is Controlled by, or is under common Control with, the subject entity. For purposes of this definition, “Control” means the possession, directly or indirectly, of the power to direct or cause the direction of the management and operating policies of the subject entity, or the ownership of more than fifty percent (50%) of its voting or equity securities, contract, voting trust, or otherwise.
“API” means Application Programming Interface and refers to any software with a distinct function.
“App” or “Mobile App” means one mobile application built and compiled for a single mobile operating system (i.e. iOS or Android), and applications with the same name/purpose built for two distinct mobile operating systems count as two (2) Apps.
“Beta Services” means new Services, or new features or functionality of an existing Service, that have not been made commercially available.
“Customer” means the entity identified in the applicable Order Form and its User(s) receiving the Services from NowSecure.
“Customer Data” means all of Customer’s proprietary data, content, software, mobile applications, or other material or information that Customer submits to, or otherwise generates in connection with, the Services. Customer Data includes Customer Reports.
“Customer Reports” means the security and vulnerability analysis and reports generated by the Services on Customer’s proprietary mobile applications that Customer uploads or provides to the Services, or which are generated based on any configuration or test data Customer uploads or provides.
“Documentation” means all user guides, documentation, specifications, training, and support materials, as updated from time to time, that are made available to Customer by NowSecure.
“Equipment” means all hardware provided to Customer by NowSecure in connection with a Subscription.
“Fees” means the fees to be paid by Customer to NowSecure or Reseller, as specified in the Order Form.
“Free/Trial Use” means any Services made available to Customer free of charge or on a no-cost subscription tier for the purpose of testing or evaluating the applicable Services.
“Harmful Content” means code, files, scripts, or programs, including viruses, worms, and Trojans, intended to deceive, disrupt, destroy, distort, disable, or otherwise do harm, but does not include access control code.
“Hosted Services” means the Services comprised of software applications hosted and operated by NowSecure and made available via the internet (also known as SaaS), as described in the applicable Order Form.
“Integration Application” means a third-party software application not provided by NowSecure that interoperates with the Services.
“Order Form” means an ordering document, schedule, statement of work, or similar instrument that specifies the Services to be provided to Customer by NowSecure.
“Pre-Existing Content” means content such as text, images, tools, computer code and/or other material, whether in written, graphical, or other form, created independent of Customer Data and used by NowSecure to provide the Services, including standard content in Software or reports. Pre-Existing Content also includes common reports for mobile applications independently tested by NowSecure without use or inclusion of any Customer Data.
“Reseller” means, if applicable, the third party specified in an applicable Order Form and authorized by NowSecure to resell Software, Services, and Equipment.
“Service Provider” means an entity providing mobile applications security assessments or analyses as a product or service, or incorporating information from mobile applications security assessments or analyses (including Customer Reports) into its products or services, for the benefit of an unaffiliated third party.
“Services” means all NowSecure products and services, including but not limited to Hosted Services and Software, and all Documentation and Pre-Existing Content associated therewith and contained therein, made available to Customer by NowSecure pursuant to an Order Form or under Free/Trial Use.
“Software” means all software and/or computer program(s), including any new versions, updates, upgrades, configurations, derivative works, or revisions thereof, made available to Customer by NowSecure in connection with the Services.
“Subscription” means the right to access and use Services for the duration, in the quantity, and at the price specified in an Order Form.
“Supplemental Services” means deployment, integration, training, and security assessment services offered by NowSecure.
“System Data” means aggregated and anonymized analytics data relating to how the Services are being used and the environment in which they are being used. The term System Data does not include Customer Data.
“Third-Party Products” means all third-party websites, services, or products referenced in, accessible through, or provided in connection with, the Services (other than those provided directly by NowSecure as part of a Service).
“User” means Customer’s or its Affiliates’ employees, contractors, and agents who are permitted to access the Services through Customer’s Account.
“Website” means the NowSecure website located at www.nowsecure.com and related subdomains.
2. RIGHTS & RESTRICTIONS
2.1 Access Grant. Subject to and conditioned on Customer’s payment of all applicable Fees and compliance with these Terms, NowSecure hereby grants Customer a limited, non-exclusive, non-sublicensable, and (except as otherwise expressly set forth herein) non-transferable right to access and use the Services and Software identified in an Order Form, for the duration identified in the Order Form, for Customer’s internal business purposes, in accordance with these Terms. Customer may, at its option, permit its Affiliates and/or contractors to access and use the Services and Software on its behalf, provided that any such access and use by an Affiliate or contractor shall be subject to these Terms and Customer is responsible for the acts and omissions of such Affiliate or contractor. This access grant may be extended to use as a Service Provider in accordance with Section 2.4-2.9 (Service Provider Use).
2.2 Ownership & License Grants. NowSecure and its licensors own and shall own all rights, title, and interest, including intellectual property rights, in and to the Services, Hosted Services, Supplemental Services, Software, Documentation, and Pre-Existing Content, including all copyright, trademark, patent or other rights under intellectual property law. Customer owns and shall own all rights, title, and interest in and to Customer Data, including all copyright, trademark, patent or other rights under intellectual property law. Customer grants NowSecure a limited, nonexclusive, nontransferable, worldwide license to host, copy, transmit, use, display, and/or process Customer Data for the duration of the Subscription period and any applicable retention period, solely for the purpose of NowSecure providing Services to Customer. Customer shall own all Customer Reports; however, to the extent Customer Reports contain Pre-Existing Content, NowSecure grants Customer a worldwide, perpetual, irrevocable, non-exclusive license to have, use, reproduce, modify, and distribute such Pre-Existing Content in conjunction with its use of Customer Reports. NowSecure reserves the right to retain and use System Data without restriction. Customer may provide NowSecure with ideas, opinions, or recommendations related to the Services (collectively “Feedback”), and Customer agrees that NowSecure may use Feedback internally to support and improve the Services without any obligation. No rights are granted by either party to the other except those expressly set forth herein.
2.3 Restrictions and Prohibited Uses. Except as otherwise expressly authorized by these Terms, Customer shall not: (a) use the Services for any unlawful purpose, or in any manner that would violate the rights of any third party; (b) modify, alter, tamper with, or make derivative works based upon the Services; (c) copy or reproduce all or any part of the Services; (d) decompile, disassemble, reverse engineer or in any way derive or attempt to derive or otherwise attempt to discover the source code or underlying ideas or algorithms of the Services, except to the extent specifically allowed by applicable law; (e) access the Services in order to build a competitive product or service or to copy any ideas, features, functions, or graphics thereof; (f) license, sublicense, sell, resell, distribute, transfer, assign, or otherwise commercially exploit the Services; (g) access or use the Services in a way intended to avoid incurring Fees or exceeding usage limits or quotas; (h) provide any third party with access to the Services; (i) upload to, or distribute through, Hosted Services any Harmful Content; (j) upload to, or distribute through, Hosted Services any nonpublic personal information (NPI, as defined by GLBA), protected health information (PHI, as defined in HIPAA), or sensitive personal information such as social security numbers; (k) knowingly interfere with or disrupt Hosted Services, the data associated therewith or contained therein, or the networks connected thereto; or (l) attempt to gain unauthorized access to the Services or their related systems or networks; or (m) engage, permit, or otherwise allow any third party to do any of the foregoing.
2.4 Service Provider Use. In the event of any conflict between this Section and other provisions of these Terms, this Section shall prevail solely with respect to Customer’s use of the Services as a Service Provider. If authorized by NowSecure in the applicable Order Form, Customer may access and use the Services as a Service Provider, subject to the additional terms set forth in this Section.
2.5 Service Provider Metering & Reporting. Customer agrees that its right to access and use the Services as a Service Provider is subject to the quantities or delivery limits purchased by Customer as specified in the applicable Order Form (“Usage”). Should Customer exceed the allowed Usage at any time, Customer agrees to purchase additional license units required to cover such additional volume. Customer agrees that the Services may incorporate features to measure and report Usage to NowSecure, and that NowSecure may monitor Usage and apply technical limits to the Services. Customer agrees NowSecure may audit Usage periodically, not more than quarterly unless for cause, and Customer agrees to reasonably assist and cooperate with such audit and provide information and records to NowSecure as required to review Usage.
2.6 Service Provider Trademark Usage. Customer may use NowSecure’s or its Affiliates’ names, tradenames, trademarks, service marks, designs, logos or symbols (“Marks”) to identify NowSecure or the Services during the term of these Terms in any deliverables provided to a third-party consumer of Customer’s products and services. Customer shall comply with NowSecure brand guidelines, and upon written request, promptly remove or modify any such use of Marks. NowSecure retains all ownership rights in the Marks, except for the limited license provided in this subsection 2.6. Upon termination of these Terms, all limited licenses granted under this subsection 2.6. shall immediately terminate, except for previously provided deliverables under this subsection.
2.7 Service Provider No Warranties / Third-Party Beneficiaries. In marketing, licensing, selling, and/or distributing its products and services, which incorporate or make use of the Services or Customer Reports, Customer will not make any representations, warranties, or guarantees to third parties on behalf of the Services, Customer Reports, and/or NowSecure. Any warranties Customer provides to a third party are made exclusively by Customer, and NowSecure shall not be a party to such warranties. Neither these Terms nor any provision herein are intended to, and shall not be construed to, give any third party (including, without limitation, any third-party purchasers of Customer’s products and services, which incorporate or make use of the Services and/or Customer Reports) any interest or rights (including, without limitation, any third-party beneficiary rights) with respect to or in connection with any terms or provision contained herein or contemplated hereby.
2.8 Service Provider Warranty Disclaimer. IN ADDITION TO THE DISCLAIMERS IN SECTION 8.4 OF THE TERMS, CUSTOMER’S PRODUCTS, SERVICES, PROGRAMS, PROJECTS, OR DELIVERABLES, WHICH INCORPORATE OR MAKE USE OF THE SERVICES AND/OR CUSTOMER REPORTS, DEPEND ON NUMEROUS FACTORS BEYOND NOWSECURE’S CONTROL; AND THEREFORE, CUSTOMER ACKNOWLEDGES THAT NOWSECURE DOES NOT MAKE ANY, AND EXPRESSLY DISCLAIMS ALL, REPRESENTATIONS AND WARRANTIES AS TO THE PROFITS OR POTENTIAL SUCCESS OF CUSTOMER’S PRODUCTS, SERVICES, PROGRAMS, PROJECTS, OR DELIVERABLES, WHICH INCORPORATE OR MAKE USE OF THE SERVICES AND/OR CUSTOMER REPORTS. CUSTOMER IS SOLELY RESPONSIBLE FOR THE ACCURACY, COMPLETENESS, AND CONTENT OF ITS REPORTS AND DELIVERABLES PRODUCED USING THE SERVICES AND/OR CUSTOMER REPORTS, AND NOWSECURE ASSUMES NO RESPONSIBILITY OR LIABILITY THEREFOR.
2.9 Service Provider Indemnification. To the fullest extent permitted by law, Customer shall indemnify, defend, and hold NowSecure and its parents, subsidiaries, officers, employees, directors, agents, and representatives harmless (“NowSecure Indemnified Parties”) against any losses, damages, or expenses, including attorneys’ fees and costs, incurred by NowSecure Indemnified Parties as a result of any suit, proceeding, claim, or other legal action by a third party that (i) arises from or is connected with Customer’s marketing, promotion, licensing, and/or sale of products and services that incorporate or make use of the Services and/or Customer Reports; (ii) is based on a claim that Customer has breached any obligations under a separate, third-party agreement; or (iii) is based on the negligent or intentional acts or omissions of Customer, while performing under any applicable sections and/or any third-party agreement. Customer’s obligations under this subsection are contingent upon (i) NowSecure Indemnified Parties providing written notice to Customer of any such claim (provided that later notice shall not relieve Customer of its liability and obligations under this subsection except to the extent that it is materially prejudiced by such later notice); and (ii) the NowSecure Indemnified Parties giving Customer authority, information, and reasonable assistance necessary to settle, compromise, or defend such claims. No settlement of any claim shall be made without the express written permission of NowSecure Indemnified Parties (and such consent cannot be unreasonably withheld). NowSecure Indemnified Parties shall have the right to participate in the defense of any claims hereunder at their own expense. This indemnification obligation shall not be limited in any way by required, actual, or available insurance. This indemnification obligation is in addition to all Customer indemnification obligations in these Terms.
3. NOWSECURE RESPONSIBILITIES
3.1 Providing the Services. NowSecure represents that it will make the Services available to Customer in accordance with these Terms and any applicable Order Form. In addition, NowSecure may from time to time, and in its discretion, utilize its Affiliates or engage third-party contractors in connection with providing or maintaining the Services, provided that: (a) any such Affiliate or third-party contractor shall be bound by written confidentiality obligations no less restrictive than those contained in these Terms; and (b) NowSecure shall be directly liable to Customer, to the extent provided in these Terms, for any breach of these Terms caused by such Affiliate or third-party contractor. NowSecure may utilize the Sub-processors specified in Schedule 4 of the Data Processing Agreement in its performance of the Services and may amend its Sub-processors from time to time by providing Customer at least thirty (30) days prior notice. If Customer objects to any Sub-processor assignment, then (a) NowSecure shall affirm it will provide the Services without the use of such Sub-processor; or (b) Customer may terminate these Terms without further obligation; and NowSecure shall refund the pro rata amount of any prepaid fees for unused Services.
3.2 Security Commitment. NowSecure will utilize appropriate technical, physical, and organizational security measures and safeguards in connection with the storage, transmission, handling, and processing of Customer Data via the Services, in order to protect Customer Data from unauthorized use, access, and disclosure, in accordance with industry best practices, Addendum C – Information Security, and Addendum D – Data Processing Agreement.
3.3 Support and SLA. NowSecure will provide product technical support as described in the applicable Order Form and Addendum A – Support and Service Level Agreement (“SSLA”) including support case tracking, prioritization, and product updates. NowSecure will ensure Hosted Services are Available in accordance with the SSLA for the applicable Service and Support Tier.
3.4 Data Backup. NowSecure will implement reasonable measures to ensure data backup for the Hosted Services, in order to support continuity of service and disaster recovery, in accordance with the SSLA.
3.5 Artificial Intelligence. NowSecure will maintain standards and procedures to apply AI safely and securely, consistent with industry best practices, such as the NIST Artificial Intelligence Risk Management Framework and the OECD Recommendation of the Council on Artificial Intelligence. NowSecure will disclose any use of AI in the Services and provide reasonable information about how AI interacts with Customer Data, and the AI model(s) used. NowSecure will ensure no Customer Data can be disclosed or leaked in violation of confidentiality obligations due to generative AI features or AI model training. Wherever feasible, NowSecure will label AI-generated output and provide Customer opt-out.
4. CUSTOMER RESPONSIBILITIES
4.1 Customer Software and Equipment. Customer agrees they are responsible for purchasing, installing, and maintaining all hardware, software, and communications equipment (except for Equipment and Software) identified in the applicable Documentation as the minimum necessary to access and use the Services, and for paying all third-party access charges (e.g., ISP, telecommunications, Integration Application fees) incurred while using the Services.
4.2 Replacement of Equipment. Customer is responsible for safeguarding the Equipment in its possession or control. If the Equipment is inoperable or malfunctioning upon delivery to Customer, NowSecure will replace such Equipment free of charge. However, if the Equipment is lost, stolen, damaged, or becomes inoperable while in Customer’s possession or control, Customer shall be responsible for all replacement costs, including shipping charges, customs taxes or duties, and all other related taxes.
4.3 Actions of Users. Customer is responsible for the actions of its users in connection with their use of Customer’s Account, the Services, the Documentation, and the Equipment, and Customer will ensure that all of its users abide by these Terms and all applicable laws, rules, and regulations.
4.4 Accounts & Credentials. In order to access and use the Services, Customer may be required to establish an Account and provide a valid form of payment when first registering with NowSecure. When registering for an Account, Customer will provide true, accurate, and complete information and will update the information as necessary to keep it current at all times. In order to access Customer’s Account, Customer and each User under Customer’s Account will register unique username(s) and password(s) (“Credentials”). Customer is entirely responsible for maintaining the security and confidentiality of its Account and each of its User’s Credentials, all Services ordered, accessed, or otherwise used in connection with its Account and its users’ Credentials, and all actions taken in connection with Customer’s Account. Customer will not share its Account or its users’ Credentials with any third party. Customer will immediately notify NowSecure of any unauthorized use of its Account, or of any breach of security or loss or theft of its users’ Credentials. Customer agrees that the use of the Service is limited to use by employees and contractors of Customer for whom applicable fees have been paid.
4.5 Data Authorization. Customer is solely responsible for ensuring it has all necessary rights, authorizations, and consents to use and share Customer Data as contemplated by these Terms.
4.6 Integration Applications. The Services may interoperate with Integration Applications. Customer acknowledges and agrees that if it utilizes Integration Applications, it is solely responsible for obtaining all necessary use rights from the applicable third party, and NowSecure shall have no obligation to Customer in connection with such Integration Applications (including without limitation any support obligation).
5. FEES AND PAYMENTS
5.1 Fees. Customer agrees to pay all Fees specified in the applicable Order Form. Unless otherwise expressly set forth in these Terms or the applicable Order Form: (a) all fees and payment obligations are non-cancelable and non-refundable; (b) quantities purchased cannot be decreased during the Subscription term; and (c) Fees are due in advance for the Subscription term. For all NowSecure Order Forms and Services, any quantity “per app” or “per application” refers to an App for a single platform.
5.2 Invoicing and Payment. Customer shall provide to NowSecure complete and accurate billing and contact information and promptly notify NowSecure of any changes to such information (or notify Reseller, if applicable). NowSecure shall deliver a commercial invoice to Customer after acceptance of an Order Form, and unless otherwise stated in the applicable Order Form, Fees are due Net thirty (30) days from the date the invoice is received. Timely payment of Fees is a material obligation.
5.3 Taxes. Fees are stated exclusive of all applicable duties, tariffs, and taxes. Customer agrees to pay, in addition to the Fees, all applicable duties, tariffs, taxes, and similar government mandated charges which result from its purchase of Services, except taxes based on NowSecure’s own income. Each party will provide and make available to the other party any exemption certificates, treaty certification, or other exemption information reasonably requested by the other party.
5.4 Future Functionality. Customer agrees that its purchase of the Services is not contingent on the delivery of any future feature or functionality, or dependent on any representations or statements made by NowSecure or any other party regarding future features or functionality.
6. FREE/TRIAL USE SERVICES & BETA SERVICES
6.1 Free/Trial Use. NowSecure may, in its discretion, provide Customer access to certain Services on a Free/Trial Use basis. If so, Customer may use such Services for its internal evaluation until the earlier to occur of: (a) the date specified in the applicable Order Form; (b) the start date of Customer’s paid Subscription for the Free/Trial Use Services; or (c) the end date identified in any notice from NowSecure terminating the Free/Trial Use period. If Customer ends a paid Subscription without notice to NowSecure, NowSecure may convert Customer to a Free/Trial Use Subscription. Additional terms and conditions may accompany the Free/Trial Use Services, and any such additional terms and conditions are hereby incorporated into these Terms. Unless Customer procures a paid Subscription for such Services prior to the end of the Free/Trial Use period, any Customer Data, personalized configurations, or output generated by or as a result of using the Services during the Free/Trial Use period, may be permanently lost.
6.2 Beta Services. NowSecure may, in its discretion, make available to Customer certain Beta Services. If so, Customer may use such Beta Services for internal evaluation. Customer understands and agrees that such Beta Services: (a) may be available for a temporary period and may be removed or modified by NowSecure at any time; (b) may not ultimately be incorporated by NowSecure into commercially available Services; and (c) may contain errors or undocumented functionality. If NowSecure discontinues the Beta Service, Customer Data, and configurations specifically related to a Beta Service, may not be retained.
6.3 Disclaimer. ALL FREE/TRIAL USE AND BETA SERVICES ARE PROVIDED “AS-IS” AND WITHOUT ANY WARRANTY AND ARE EXCLUDED FROM ANY REPRESENTATIONS OR WARRANTIES SET FORTH IN THESE TERMS.
7. CONFIDENTIALITY
7.1 Confidential Information. In connection with the relationship and obligations created by these Terms, NowSecure and Customer may deliver to each other Confidential Information (the party disclosing such information or materials being the “Disclosing Party” and the party receiving such information or materials being the “Receiving Party”). “Confidential Information” means nonpublic information that Disclosing Party designates as being confidential or proprietary, or which under the circumstances surrounding disclosure reasonably ought to be treated as confidential. Confidential Information includes, without limitation, (a) information relating, in whole or in part, to released or unreleased Disclosing Party’s technical, financial, pricing, customer, client, member, personnel, regulatory, and/or other business information in written, graphic, oral, visual or other tangible or intangible forms including, but not limited to, financial statements and other financial data, specifications, patent applications, records, data, computer programs, drawings, schematics, know-how, notes, models, reports, policies, processes, and samples; (b) proprietary or confidential material or trade secrets of Disclosing Party, Disclosing Party software or hardware products, the marketing or promotion of any Disclosing Party product, Disclosing Party’s business policies or practices, and information received or derived from third parties that Disclosing Party is obligated to treat as confidential; (c) the names, addresses, telephone numbers, email addresses, assets, or other nonpublic personal information regarding the parties’ clients and consumers. Customer Confidential Information includes Customer Data. NowSecure Confidential Information includes the Services, Documentation, Pre-Existing Content including common reports, and pricing terms related thereto. Confidential Information excludes information that the Receiving Party can demonstrate, through written or other documentary records: (a) was rightfully in the Receiving Party’s possession without obligation of confidentiality prior to receipt from the Disclosing Party; (b) has become publicly known or is otherwise generally available to the public through no action or fault of the Receiving Party; (c) was rightfully furnished to the Receiving Party by a third party without restriction on disclosure or use; or (d) was independently developed by the Receiving Party without use of or reference to the Disclosing Party’s Confidential Information.
7.2 Protection of Confidential Information. The Receiving Party will: (a) hold the Confidential Information of the Disclosing Party in trust and confidence and not disclose such Confidential Information to any third party except as provided herein; (b) not use the Confidential Information of the Disclosing Party for any purpose except for the purposes described in these Terms; (c) use the same degree of care to protect the Disclosing Party’s Confidential Information as it uses to protect the confidentiality of its own confidential information of like kind, but in no event less than a reasonable degree of care; and (d) except as otherwise authorized by the Disclosing Party in writing, limit disclosure of the Disclosing Party’s Confidential Information to its Affiliates, financial and legal advisors, its employees or agents who have a need to know and who are bound, either in connection with their relationship, employment, or representation, by confidentiality obligations no less restrictive than the confidentiality obligations contained herein. Receiving Party shall be responsible for its agents or employees, to whom it has disclosed Confidential Information, in compliance with these Terms. Customer shall not remove or destroy any proprietary markings or restrictive legends placed upon or contained in the Services, the Documentation, or output generated thereby. Receiving Party shall promptly notify the Disclosing Party upon becoming aware of a breach or threatened breach hereunder, and shall cooperate with any reasonable request of the Disclosing Party in enforcing its rights.
7.3 Compelled Disclosure. Notwithstanding the foregoing, the Receiving Party may disclose Confidential Information in response to a court order, or as otherwise required by law or applicable court of jurisdiction, provided that: (a) the Receiving Party gives the Disclosing Party reasonable prior notice of the required disclosure (to the extent legally permitted) and reasonable assistance, at the Disclosing Party’s cost, if the Disclosing Party wishes to contest the disclosure or obtain a protective order prior to disclosure, (b) the Receiving Party shall disclose only that portion of the Confidential Information that the Receiving Party is legally required to disclose; and (c) the Disclosing Party has the opportunity to remove information that is not required to be disclosed.
7.4 Survival. Receiving Party’s obligations regarding Confidential Information will survive the expiration or termination of the Terms, and all obligations of confidentiality and non-disclosure shall continue for three (3) years after the expiration or termination of these Terms, except such obligations of confidentiality and non-disclosure will survive with respect to trade secrets for so long as any such Confidential Information remains a trade secret under applicable law.
8. REPRESENTATIONS, WARRANTIES, AND DISCLAIMERS
8.1 Mutual Representations. Each party represents and warrants to the other that: (a) it has all necessary right, power, and authority, and has taken all necessary action to enter into and perform its obligations under these Terms and to grant the rights granted to the other party herein; (b) it will abide by all laws, rules, and regulations applicable to its performance under these Terms; and (c) its execution and performance of these Terms will not violate or conflict with the rights of any third party or with any confidentiality or other agreement to which it is a party or by which it is bound.
8.2 NowSecure Representations. NowSecure represents and warrants to Customer that: (a) the Services (except for Free/Trial Use and Beta Services) will function in all material respects in conformity with the applicable Documentation; and (b) the Services will not knowingly contain any Harmful Content. The warranties set forth herein shall not apply to any error, interruption, other non-conformity, or Harmful Content caused by: (i) Customer’s use of the Service not in conformity with the applicable Documentation; (ii) Customer’s or any third party’s network configuration, connection, equipment, hardware, or software; (iii) Customer Data; or (iv) Customer’s breach of these Terms.
8.3 Customer Warranties. Customer represents and warrants to NowSecure that: (a) it owns, or has obtained from the owner of, all authorizations, consents, permissions, and licenses necessary for Customer and NowSecure to utilize Customer Data in connection with the Services, and for the Services to process and store Customer Data in the manner identified in the Documentation and these Terms; (b) Customer Data does not and will not infringe, misappropriate, or otherwise violate any intellectual property rights or any privacy or other rights (including contractual rights) of any third-party or violate any applicable law; and (c) Customer Data does not and will not contain any Harmful Content.
8.4 Disclaimers. UNLESS OTHERWISE EXPRESSLY SET FORTH HEREIN, CUSTOMER’S USE OF THE SERVICES WILL BE AT ITS OWN RISK AND ALL SERVICES ARE PROVIDED “AS IS”, “AS AVAILABLE”, AND “WITH ALL FAULTS”, AND NOWSECURE AND ITS LICENSORS DISCLAIM ALL WARRANTIES, CONDITIONS, AND REPRESENTATIONS, WHETHER STATUTORY, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, ANY IMPLIED WARRANTIES, OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT AND ALL WARRANTIES ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. NOWSECURE MAKES NO WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE OR NON-INFRINGEMENT. NOWSECURE DOES NOT WARRANT THAT CUSTOMER’S USE OF THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE. NOWSECURE IS NOT LIABLE FOR DELAYS, FAILURES OR PROBLEMS INHERENT IN USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE NOWSECURE’S CONTROL. NO ORAL OR WRITTEN INFORMATION OR ADVICE PROVIDED BY NOWSECURE OR ANY OF ITS EMPLOYEES WILL CREATE A WARRANTY, CONDITION, OR REPRESENTATION OF ANY KIND. THE FOREGOING DISCLAIMER WILL APPLY TO THE FULLEST EXTENT PERMITTED BY LAW, AND WILL SURVIVE ANY TERMINATION OR EXPIRATION OF THESE TERMS. SOME JURISDICTIONS MAY NOT ALLOW CERTAIN EXCLUSIONS OR LIMITATIONS, AND IN SUCH EVENT NOWSECURE’S WARRANTIES AND REPRESENTATIONS WILL BE LIMITED TO THE GREATEST EXTENT PERMITTED.
8.5 High Risk Activities. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING DISCLAIMERS, THE SERVICES, AND ANY RESULTS OBTAINED FROM THE SERVICES, ARE NOT INTENDED FOR USE IN THE OPERATION OF, OR IN CONNECTION WITH THE OPERATION OF, NUCLEAR OR CHEMICAL PROCESSING FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL SYSTEMS, LIFE SUPPORT MACHINES, OR OTHER EQUIPMENT OR SYSTEMS IN WHICH THE FAILURE OF THE SERVICES COULD LEAD TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE.
9. INDEMNIFICATION
9.1 NowSecure’s Indemnification of Customer. With the exception of Free/Trial Use and Beta Services, NowSecure shall indemnify, defend, and hold Customer harmless against any losses, damages, or expenses, including attorneys’ fees and costs, incurred by Customer as a result of any suit, proceeding, claim, demand or other legal action (“Claim”) alleging that Customer’s authorized use of the Services infringes on a third party’s intellectual property rights. NowSecure will not have any obligation to indemnify, defend, or hold Customer harmless where the Claim could have been avoided but for Customer’s: (a) access to or use of the Services in combination with any hardware, system, software, network, or other materials or services not provided or authorized in writing by NowSecure; (b) modification of the Services, or modifications made by NowSecure to the Services on Customer’s behalf; (c) failure by Customer to timely implement any modifications, upgrades, replacements, or enhancements NowSecure made available to Customer; or (d) breach of these Terms. If NowSecure receives information about an infringement claim related to the Services, NowSecure may in its discretion: (i) modify the Services so that they no longer infringe, but are substantially, functionally equivalent; (ii) obtain a license for Customer’s continued use of the affected Services; or (iii) terminate Customer’s Subscription for the affected Service upon thirty (30) days’ written notice with a refund of any unused, prepaid fees. NowSecure will not have any obligation to indemnify, defend, or hold Customer harmless for any alleged or actual infringement, or damages related thereto, resulting from Customer’s continued use of the affected Service after NowSecure’s written notice to Customer to cease use thereof in order to avoid further infringement.
9.2 Customer’s Indemnification of NowSecure. Customer and/or its Affiliates shall indemnify, defend, and hold NowSecure and its parents, subsidiaries, officers, employees, directors, agents, and representatives (“NowSecure Indemnified Parties”) harmless against any losses, damages, or expenses, including attorneys’ fees and costs, incurred by NowSecure Indemnified Parties as a result of any Claim alleging that Customer Data and NowSecure’s authorized use thereof, or Customer’s use of the Services (including to test any third-party App provided by Customer) infringes on a third party’s intellectual property, legal or contractual rights. This obligation shall not apply when a claim is caused by NowSecure’s violation of these Terms.
9.3 Indemnification Requirements. The following requirements apply to any Claim under Sections 9.1 and 9.2: (a) the indemnified party shall provide prompt written notice to the indemnifying party of the Claim; (b) the indemnified party shall tender to the indemnifying party sole control of the defense and settlement negotiations related to the Claim; (c) the indemnified party shall reasonably assist (at indemnifying party’s expense) in the defense or settlement of the Claim; (d) the indemnified party shall avoid taking any action that would be prejudicial to the defense of the Claim; (e) the indemnified party agrees to take all reasonable steps to mitigate losses; (f) the indemnifying party may not settle any Claim in any manner that imposes any admission of guilt or liability on the indemnified party without the prior written consent of the indemnified party; and (g) the indemnified party may participate in the defense of the Claim, at its expense, with counsel of its choice.
10. LIMITATION OF LIABILITY
10.1 Exclusion of Certain Claims. EXCEPT AS OTHERWISE PROVIDED IN SECTION 10.3, TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, EXEMPLARY, SPECIAL, PUNITIVE, OR CONSEQUENTIAL LOSS, DAMAGE, COST, OR EXPENSE WHATSOEVER, INCLUDING WITHOUT LIMITATION, ANY LOSS OF PRODUCTION, LOSS OR CORRUPTION OF DATA, LOSS OF PROFITS OR OF CONTRACTS, OR LOSS OF BUSINESS OR OF REVENUES UNDER ANY THEORY OF LIABILITY, WHETHER BASED IN CONTRACT, TORT, NEGLIGENCE, PRODUCT LIABILITY, BREACH OF WARRANTY, MISREPRESENTATION OR OTHERWISE. ANY CAUSE OF ACTION ARISING OUT OF OR RELATED TO THE SERVICES MUST BE COMMENCED WITHIN TWO (2) YEARS AFTER THE CLAIM OR CAUSE OF ACTION ACCRUES, OTHERWISE SUCH CLAIM OR CAUSE OF ACTION SHALL BE TIME-BARRED.
10.2 Limitation of Liability. EXCEPT AS OTHERWISE PROVIDED IN SECTION 10.3, IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER PARTY, OR ANY THIRD-PARTY, FOR AN AMOUNT GREATER THAN THE TOTAL FEES PAID OR PAYABLE FOR THE SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE DATE ON WHICH THE LIABILITY AROSE. THE ABOVE LIMITATIONS WILL APPLY WHETHER AN ACTION IS IN CONTRACT OR TORT AND REGARDLESS OF THE THEORY OF LIABILITY.
10.3 Exceptions. NO LIMITATION OF LIABILITY SHALL APPLY TO CLAIMS ARISING FROM (A) A PARTY’S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT; (B) A PARTY’S WILLFUL OR NEGLIGENT BREACH OF ITS CONFIDENTIALITY OBLIGATIONS UNDER SECTION 7; OR (C) A PARTY’S INDEMNITY OBLIGATIONS UNDER SECTION 9.
10.4 Nature of Limitation. THIS LIMITATION WILL APPLY REGARDLESS OF WHETHER A PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF THOSE DAMAGES AND REGARDLESS OF WHETHER ANY REMEDY FAILS OF ITS ESSENTIAL PURPOSE. EACH PARTY ACKNOWLEDGES THAT THE FOREGOING LIMITATIONS FORM AN ESSENTIAL BASIS OF THE BARGAIN BETWEEN THE PARTIES. THE EXCLUSIONS AND LIMITATIONS IN THIS SECTION WILL SURVIVE ANY TERMINATION OR EXPIRATION OF THESE TERMS.
11. TERM AND TERMINATION
11.1 Term. These Terms are effective as of the Effective Date and will continue to bind the parties until the earlier of: (a) termination by either party in accordance with this Section 11; or (b) twelve (12) months after termination or expiration of all Subscriptions (including Free/Trial Use). The term of the applicable Subscription shall be as specified in the relevant Order Form.
11.2 Termination for Cause. Either party may terminate these Terms, individual Order Forms, or individual Subscriptions immediately upon written notice to the other party if: (a) the other party commits any material breach of these Terms and fails to cure such breach within thirty (30) days after written notice thereof from the non-breaching party; or (b) if the other party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, liquidation, or assignment for the benefit of creditors, or otherwise becomes generally unable to pay its debts. In addition, Customer may terminate these Terms, individual Order Forms, or individual Subscriptions immediately upon notice to NowSecure as provided in the SSLA. If these Terms, individual Order Forms, or individual Subscriptions are terminated by Customer for cause under this Section 11.2, NowSecure agrees to refund Customer’s prepaid Fees covering the unused portion of the applicable Subscription period remaining after the effective date of termination. If these Terms, individual Order Forms, or individual Subscriptions are terminated by NowSecure for cause, Customer agrees to pay NowSecure any unpaid Fees for the entire Subscription period for the terminated Services.
11.3 Termination for Convenience. Customer may terminate these Terms, individual Order Forms, or individual Subscriptions at its convenience, with thirty (30) days prior written notice. Either party may terminate these Terms if there are no active Subscriptions upon thirty (30) days prior written notice. In no event will termination under this Section 11.3 relieve Customer of its obligation to pay NowSecure any Fees for Services Customer purchased from NowSecure prior to such termination, or entitle Customer to a refund for any Fees already paid by Customer to NowSecure for the Services, including pre-paid subscription fees.
11.4 Effect of Termination of Terms. If these Terms are terminated for any reason: (a) all Order Forms and Subscriptions will terminate; (b) all rights, licenses, consents, and authorizations granted herein by either party to the other will be revoked, except for those explicitly stated herein as irrevocable, and such revocation will be immediate, except where a transition period is explicitly provided herein; (c) NowSecure will disable Customer’s access to all Services; (d) Customer shall pay for all Subscriptions up to the effective date of termination, which in the case of annual Subscriptions or longer shall be the full amount, and any termination Fees if specified in the relevant Order Form (except where Customer is terminating these Terms for cause as provided in Section 11.2); (e) Customer will immediately cease all use of the Services; (f) Customer may export Customer Data and NowSecure will delete Customer Data in accordance with these Terms; and (g) for all other Confidential Information the Receiving Party will promptly destroy, or at the Disclosing Party’s request return, all Confidential Information of the Disclosing Party. Notwithstanding anything to the contrary in the foregoing, with respect to Confidential Information of the Disclosing Party that may reside in electronic form in the Receiving Party’s backups, archives, and disaster recovery systems, the Receiving Party may retain such Confidential Information for the period required by applicable law, or for the period that is consistent with the Receiving Party’s standard electronic records retention policies applicable to the media on which such Confidential Information is stored, whichever is longer. Upon expiration of the applicable period, the Receiving Party will erase, destroy, or overwrite the media containing the Disclosing Party’s Confidential Information. The confidentiality obligations contained in these Terms shall continue to bind the Receiving Party until such time as the Disclosing Party’s Confidential Information is returned, erased, destroyed, or overwritten.
11.5 Effect of Termination of Individual Order Forms or Subscriptions. In the event of expiration or termination of individual Order Forms or Subscriptions for any reason, upon the effective date of such expiration or termination: (a) all rights, licenses, consents, and authorizations granted by either party to the other under the affected Order Forms or Subscriptions will cease immediately; (b) NowSecure will disable Customer’s access to all affected Services; (c) Customer shall pay for all Subscriptions up to the effective date of termination, which in the case of annual Subscriptions shall be the full amount, and any termination Fees if specified in the relevant Order Form (except where Customer is terminating these Terms for cause as provided in Section 11.2); and (d) Customer will immediately cease all use of the affected Services.
12. PRIVACY
Customer and NowSecure agree to comply with all applicable data protection and privacy laws, as indicated in NowSecure’s Privacy Policy, available at https://www.nowsecure.com/legal/privacy-notice/ (including but not limited to California Consumer Privacy Act [“CCPA”] and General Data Protection Regulation [“GDPR”]), while operating under these Terms. Customer shall ensure that any and all information or data, including without limitation, personal information and data, used by Customer in connection with the Services is collected, processed, transferred, and used in full compliance with applicable data protection laws and that it has obtained all necessary authorizations and consents from any data subjects to process personal information and data. If required by applicable data protection and privacy laws, the parties will enter into standard contractual clauses for the transfer of any Customer Data outside of the European Union, United Kingdom, or the applicable jurisdiction requiring such contractual clauses.
Customer Data may be hosted or processed by NowSecure, and its respective authorized Sub-processors, in the United States. To the extent NowSecure is required to process personal information on Customer’s behalf, the terms in the applicable Data Processing Agreement shall apply.
13. GENERAL PROVISIONS
13.1 Modification. Except as otherwise provided herein, no modification, amendment, or waiver of any provision of these Terms will be effective unless in writing and signed by the party against whom the modification, amendment, or waiver is to be asserted. The parties agree that any term or condition stated in a Customer purchase order document is not a binding modification to these Terms. Notwithstanding the foregoing, NowSecure may modify these Terms from time to time by posting a revised version of these Terms on the Website with an updated Effective Date. Customer’s continued access to or use of the Services following such posting constitutes Customer’s acceptance of the modified Terms.
13.2 Notices. Except as otherwise specified by these Terms, all notices or reports permitted or required under these Terms will be in writing and delivered by personal delivery, electronic mail, or by certified or registered mail, return receipt requested, and will be deemed given upon personal delivery, five (5) days after deposit in the mail, or upon acknowledgement of receipt of electronic transmission. Notices to NowSecure will be sent to: NowSecure, Inc., ATTN: General Counsel, 141 W Jackson Blvd Ste 1325, Chicago, IL 60604, Email: [email protected]. Notices to Customer will be sent to the email address of the administrator(s) designated on Customer’s Account.
13.3 Mediation. If a dispute arises out of or relates to these Terms or the breach thereof, and if the dispute cannot be settled through direct discussions or negotiation, the parties agree first to try in good faith to settle the dispute by mediation administered by the American Arbitration Association under its Commercial Mediation Procedures before resorting to arbitration, litigation, or any other dispute resolution procedure. The place of mediation shall be Chicago, Illinois, U.S.A., and the language of the mediation shall be English.
13.4 Governing Law. These Terms shall be governed by and construed in accordance with the laws of the State of New York, U.S.A. without regard to its conflict of law provisions. The parties agree that (i) the United Nations Convention on Contracts for the International Sale of Goods shall not apply to these Terms, and (ii) the Uniform Computer Information Transactions Act shall not apply to these Terms, even if any performance under these Terms would implicate the laws of a jurisdiction which has adopted such laws/acts.
If Customer is incorporated in the U.S.A., each party consents to and agrees that each party is subject to the exclusive jurisdiction of the state and federal courts of the State of New York with respect to any action for enforcement of or any dispute arising out of these Terms.
If Customer is incorporated outside of the U.S.A., each party consents to and agrees that each party is subject to arbitration administered by the International Centre for Dispute Resolution with respect to any action for enforcement of or any dispute arising out of these Terms. The arbitration shall be administered in accordance with the ICDR International Arbitration Rules. The seat of the arbitration shall be in Chicago, Illinois, U.S.A., the Tribunal shall consist of one (1) arbitrator, and the language of the arbitration shall be English.
13.5 Force Majeure. Except for payment obligations, each party shall be excused from failure to perform its obligations hereunder if such failure results from causes beyond its reasonable control, including without limitation, acts of God, pandemic or epidemics, acts of civil or military authority, civil unrest, insurrections, war, terrorist acts, boycotts, embargoes, labor strikes, natural disasters, or internet or telecommunications failures (collectively “Force Majeure Events”). If a Force Majeure Event prevents or delays a party’s performance, it will promptly notify the other party in writing, and will use all commercially reasonable efforts to resume performance if and when possible. Either party may terminate these Terms if a Force Majeure Event prevents or delays performance for a period of thirty (30) days or more.
13.6 Export Compliance. The Software, Equipment, and Documentation may be subject to U.S. export control laws, and may be further subject to export or import regulations in other countries. If such regulations are applicable, Customer agrees to comply with all such regulations and acknowledges that it is Customer’s responsibility to obtain all necessary licenses to import and re-export the Software, Equipment, and Documentation outside the U.S. The Software, Equipment, and Documentation may not be distributed (or downloaded in the case of Software and Documentation), or otherwise exported or re-exported: (a) into, or to a national or resident of, any country to which the U.S. at any time has embargoed goods or trade restrictions; or (b) to anyone on the U.S. Treasury Department’s list of Specially Designated Nationals or on the U.S. Commerce Department’s Denied Persons, Denied Entities, and Unverified lists.
13.7 Federal Use. The Software and related Documentation are “Commercial Items,” as that term is defined at 48 C.F.R. § 2.101, consisting of “Commercial Computer Software” and “Commercial Computer Software Documentation,” as such terms are used in 48 C.F.R. § 12.212 or 48 C.F.R. § 227.7202, as applicable. Consistent with 48 C.F.R. Section 12.212 or 48 C.F.R. Section 227.7202-1 through 227.7202-4, as applicable, the Commercial Computer Software and Commercial Computer Software Documentation are being licensed to U.S. Government end users (a) only as Commercial Items and (b) with only those rights as are granted to all other end users pursuant to the terms and conditions herein. Unpublished rights are reserved under the copyright laws of the United States.
13.8 Assignment. Neither party may assign or otherwise transfer any of its rights or obligations hereunder, whether voluntarily, involuntarily, by operation of law or otherwise, without the other party’s prior written consent, which will not be unreasonably withheld. Notwithstanding the foregoing, either party may assign or otherwise transfer its rights or obligations under these Terms by operation of law or otherwise in connection with a change in control, defined as a sale of 51% or more of the company’s ownership, or the sale of all or substantially all of the assets of such party, or the assets to which these Terms pertain, without the other party’s prior written consent (“Change of Control”), provided that the party subject to the Change of Control notifies the other party in writing of such Change of Control within thirty (30) days thereafter. Subject to the foregoing, these Terms will bind and inure to the benefit of the parties, their respective successors, and permitted assigns. Any nonconforming assignment or transfer shall be null and void.
13.9 Relationship of the Parties. Nothing in these Terms shall be deemed to create a joint venture, partnership, or agency relationship between the parties or be deemed to authorize either party to incur any liabilities or obligations on behalf of, or in the name of, the other.
13.10 Third-Party Beneficiaries. There are no third-party beneficiaries under these Terms. Customer’s users, specifically, are not third-party beneficiaries under the Terms.
13.11 No Waiver. The failure of a party to take any action or to demand compliance with these Terms shall not be deemed a waiver of any right or remedy of that party, nor shall any failure to pursue rights pursuant to these Terms, including any investigation or any demand for partial relief or for compliance with these Terms in a single instance, be deemed to constitute a waiver by the party taking such action or making such demand of any right or remedy hereunder. In no event will any waiver of any particular term or provision of these Terms or in any particular instance be deemed a waiver of any subsequent occurrence under the same or any other term or provision contained herein. No waiver of any right or remedy shall be binding on any party unless it is in writing and is signed by the party to be charged.
13.12 Survival. The following Sections, and any other right or obligation of the parties in these Terms that, by its nature, should survive termination or expiration of these Terms, will survive any expiration or termination of these Terms: 2.2 Ownership & License Grants; 5.1 Fees (to the extent outstanding); 5.3 Taxes (to the extent applicable); 7 Confidentiality; 8 Representations, Warranties and Disclaimers; 9 Indemnification; 10 Limitation of Liability; 13.2 Notices; and 13.4 Governing Law.
13.13 Severability. If any provision contained herein shall for any reason be held invalid, illegal, or unenforceable in any respect by a court of competent jurisdiction, to such extent such provision shall be deemed null and void and severed from these Terms, the remainder hereof shall remain in full force and effect.
13.14 Construction. The section headings used throughout these Terms are for convenience of reference only and shall have no effect upon the construction or interpretation of these Terms or any part thereof. The use of the singular or plural form shall include the other form and the use of the masculine, feminine, or neuter gender shall include the other genders. In construing or interpreting these Terms, the word “including” shall not be limiting, and the words “hereunder” and “herein” mean within these Terms, including its attachments. The parties agree that any principle of construction or rule of law that provides that an agreement shall be construed against the drafter shall not apply to these Terms.
13.15 Entire Agreement. These Terms, including all addenda, relevant Order Forms, other attachments, and any associated terms and policies referenced and incorporated hereunder and thereunder, comprise the entire agreement regarding Customer’s use of the Services and supersedes all prior and contemporaneous agreements, proposals, or representations, written or oral, concerning its subject matter.
ACCEPTANCE. By executing an Order Form that references these Terms, or by accessing or using the Services, Customer agrees to be bound by these Terms as of the Effective Date.
ADDENDUM A
SUPPORT AND SERVICE LEVEL AGREEMENT
This Support and Service Level Agreement (“SSLA”) addresses product support, issue reporting, uptime commitment for Hosted Services, and descriptions of the applicable Service & Support Tiers. This SSLA is not applicable to Free/Trial Use Services, Beta Services, or Supplemental Services. This SSLA incorporates the Terms and any capitalized terms not defined in this SSLA will have the meanings set forth in the Terms.
- DEFINITIONS
“Available” means all material functions of the Services are operational.
“Business Hours” means NowSecure’s standard business operating hours, Monday through Friday (excluding U.S. holidays) from 8:00 a.m. to 6:00 p.m. U.S. Central Time.
“Critical Issues” means major issues preventing all or nearly all effective use of the affected Service.
“Downtime” means a period when the Hosted Services are not Available, outside of Scheduled Maintenance Periods, for reasons other than Exclusions.
“Exclusions” means any period when the Hosted Services are not available: (a) caused by factors outside of NowSecure’s reasonable control, including any Force Majeure Event or network outage or disruption outside the data center hosting the Hosted Services; (b) that results from any action or inaction by Customer or any third party acting on Customer’s behalf; (c) caused by Customer’s software or hardware, or third-party software or hardware not supplied by NowSecure; or (d) arising from NowSecure’s suspension or termination of Customer’s Subscription in accordance with the Terms.
“Product Support” means written or verbal information provided for user assistance, troubleshooting, and advice regarding the access to and use of the Services.
“Regular Issues” means common problems, user questions, or less-serious bugs.
“Service Credits” are defined in 3.4 (Service Credits) below.
“Scheduled Maintenance” means limited pre-announced time periods when Services have reduced functionality or become unavailable for purposes of scheduled maintenance.
“Serious Issues” means significant issues preventing effective use of one or more Service features.
“Service and Support Tier” means the service tier product specified on the applicable Order Form.
“Uptime Percentage” means the proportion of time during each calendar month when the Services are Available, as a percentage (Available minutes/total minutes), where total minutes in the month excludes Scheduled Maintenance and other Exclusions (both defined herein).
- PRODUCT SUPPORT
- Product Support. NowSecure will provide Product Support via website, telephone, email, and other methods made available by NowSecure, in accordance with the terms of Customer’s applicable Service and Support Tier. NowSecure may reasonably limit the number of users eligible for direct Product Support, commensurate with the level of services included in Customer’s Subscription. The standard specifications of Service and Support Tiers are included as SSLA Exhibit A.1, and in the case that the applicable Order Form includes product support specifications, such Order Form specifications shall govern.
- Support Contacts. Product support phone number(s), web submission form(s), and email contact(s) (“Support Contacts”) are provided at https://support.nowsecure.com, and Customer may submit support requests to the Support Contacts on a 24 hour, 7 days a week basis.
- Response Time. For support requests received during Business Hours, NowSecure will respond to Customer’s support requests as follows:
- Within one (1) hour for Critical Issues;
- Within two (2) hours for Serious Issues; and
- Within one (1) business day for Regular Issues.
- Customer Cooperation. Customer agrees to cooperate and work with NowSecure to reproduce errors, including conducting diagnostic or troubleshooting activities, as reasonably requested and appropriate.
- Case Tracking and Resolution. All support requests submitted to the Support Contacts are assigned a case ID and tracked through resolution. NowSecure will initiate remediation promptly for Critical and Serious Issues and work until such issues are resolved or an acceptable workaround provided. For Customers entitled to SLA Commitment, any Critical Issue not resolved or remediated through reasonable workaround within two (2) business hours of NowSecure’s receipt of Customer’s support request will be considered Downtime under the SLA Uptime Commitment (specified below), counted from the time NowSecure receives Customer’s initial request.
- Escalation. Customer may escalate any reported Critical or Serious Issues, or issues not resolved to Customer’s satisfaction, to NowSecure’s VP or Director of Customer Success.
- Live Help. NowSecure may provide a chat-based help within the Services, or via external service such as a shared Slack channel (“Live Help”) available at certain times, whereby NowSecure personnel synchronously communicate with Customer users. For Live Help conversations, no case ID will be tracked unless specifically requested by Customer. NowSecure shall generally have sole discretion in establishing availability of Live Help. Where Live Help is a feature of Customer’s Service and Support Tier, NowSecure will make commercially reasonable efforts to respond to customer requests but makes no specific response time commitment.
- Individual App Test Standard. Certain Services enable automated testing of Mobile Apps on mobile platform versions specified in the Documentation. For technical reasons (including development implementations, test configuration, app security protections, and compatibility issues) a specific app may not complete an automated test cycle, even when such app has completed test(s) in the past. In the case where an app test cycle does not complete, NowSecure will attempt to troubleshoot the cause and assist Customer in any required changes to enable automated test completion. If an app cannot complete automated testing for any reason, NowSecure may, at its option, complete comparable testing with human intervention, or credit Fees related to the affected app. When the Hosted Services are Available, incomplete automated testing of specific app cycle(s) shall not be considered Downtime.
3. SERVICE LEVEL STANDARDS
3.1 Hosted Services Availability. NowSecure will generally make the Hosted Services Available 24 hours per day, 7 days per week, and will implement monitoring to validate and track service availability. Service status tracking and notices will be published online at https://status.nowsecure.com, and Customer shall be able to subscribe to receive notices regarding service interruptions or Scheduled Maintenance.
3.2 SLA Uptime Commitment. For customers with Service and Support Tiers explicitly including “SLA Commitment,” NowSecure will make the Hosted Services Available with a minimum of at least 99.5% Uptime Percentage, in each monthly period. In the event NowSecure does not meet the required Uptime Percentage during any calendar month, Customer will be eligible to receive a Service Credit as described below.
3.3 Scheduled Maintenance. Scheduled Maintenance will be performed outside of Business Hours, and unavailability during Scheduled Maintenance will not exceed four (4) hours per month. NowSecure will provide notice to Customer through the NowSecure status portal at least twenty-four (24) hours in advance for Scheduled Maintenance with expected duration of less than one (1) hour, and at least five (5) days in advance for any Scheduled Maintenance which will require suspension of all or the majority of the Services for a period of more than one (1) hour.
3.4 Service Credits. For customers with Service and Support Tiers explicitly including SLA Uptime Commitment, Service Credits will be provided, as specified in the following table, for any month NowSecure fails to meet the required Uptime Percentage, subject to the Service Credit procedures and requirements. Service Credit days will be applied to Customer’s Subscription by extending the duration of Customer’s Subscription by the specified number of credit days.
| Monthly Uptime Percentage | Service Credit |
| Less than 99.5% but equal to or greater than 99% | 1 day |
| Less than 99% but equal to or greater than 95% | 7 days |
| Less than 95% but equal to or greater than 90% | 15 days |
| Less than 90% | 30 days |
To receive a Service Credit, Customer must submit a claim by opening a support request within ten (10) days of the end of the month in which the required Uptime Percentage was not met. The email should state “SLA Credit Request” in the subject line, and must specify: (a) the particular Service related to the claim; (b) the dates and times of each Downtime claimed; and (c) logs and other material that document and corroborate the claimed Downtime(s) (any confidential or sensitive information in these logs should be removed or replaced with asterisks). NowSecure reserves the right to withhold any Service Credit if: (i) it cannot verify the Downtime(s) or reasonably verify that the Services were not Available during the reported time; or (ii) the Downtime is subject to an Exclusion.
3.5 Reasonable Technical Controls. NowSecure may implement reasonable technical controls and limits to protect the security and availability of the Services, including but not limited to API rate controls, user creation/approval controls, email validation, account security lockouts, bot prevention (e.g. captcha), and denial-of-service protections.
4. SOFTWARE UPDATES
4.1 Updates. An Update means a modification to any feature or functionality of the Services for reasonable purposes including: (a) enhancements, corrections, bug fixes, and user interface changes; (b) necessary for stability, security, access or interoperability; or (c) in the opinion of NowSecure’s legal counsel, necessary to comply with applicable law or contract restrictions.
4.2 On-Premises Software Updates. During the term, NowSecure will provide Customer all generally released Updates to on-premises Software that is part of the Services, where applicable, including security patches, bug fixes, modifications, or enhancements. In order to apply Updates, Customer may be required to update software dependencies, including the operating system or other components. All Updates are provided for the current software version, and patches or bug fixes to prior versions are not provided.
4.3 Hosted Services Updates. During the term, NowSecure will make Updates to the Hosted Services, including any web application or API that is part of the Services, where applicable.
4.4 Negative Impact from an Update. If an Update removes a material feature or functionality of the Service, NowSecure will use commercially reasonable efforts to inform Customer of the removal at least thirty (30) days prior to release of the Update, except in the event the Update is being made in connection with purposes (b) or (c) in Section 4.1, in which case NowSecure will notify Customer as promptly as possible. If an Update removes a material feature or function, causing material detriment to Customer’s benefit of using the Services (“Negative Impact”), Customer may notify NowSecure of such Negative Impact within thirty (30) days after the release of the Update, and NowSecure shall cure the Negative Impact within thirty (30) days after receiving notice. If NowSecure has not provided a sufficient remedy in the allotted time, Customer may terminate the affected Subscription without penalty upon written notice and NowSecure shall refund the pro rata amount of any unused prepaid fees. NowSecure’s foregoing duty to cure Negative Impacts of an Update shall not apply to functions that are dependent on mobile platform components outside NowSecure’s control.
5. BACKUPS AND DISASTER RECOVERY
5.1 Disaster Recovery Program. During the term, NowSecure will create regular data backups, and maintain data and service restoration procedures, to protect against Customer Data loss and enable recovery from disruptive events such as natural disaster, cyberattack, or equipment failure, collectively constituting a “Disaster Recovery Program.” NowSecure will maintain and regularly test (at least annually) the Disaster Recovery Program, and provide evidence to Customer upon request that the Disaster Recovery Program is effective.
5.2 RTO and RPO. NowSecure’s Recovery Time Objective (RTO) in accordance with the SLA Uptime Commitment, is four (4) hours, and the Recovery Point Objective (RPO) to avoid Customer Data loss is two (2) hours.
5.3 Limitations. The Hosted Services do not contain archival backup capabilities to retrieve prior versions of modified or deleted Customer Data, and Customer is responsible for making its own data exports for any archival purpose using the provided data export features. NowSecure is not responsible for the modification or deletion of Customer Data by Customer, and Disaster Recovery Program data backups cannot be used to retrieve data modified or deleted by Customer.
6. CUSTOMER DATA EXPORT AND REMOVAL
6.1 Customer Data Export and Deletion. Throughout the applicable Subscription term and for thirty (30) days after termination, NowSecure will provide to Customer, through an industry-standard format, access and functionality to export their Customer Data from the Services. NowSecure will delete Customer Data (a) upon termination or expiration of all Services hereunder; (b) upon written request from Customer delivered via support request; or (c) automatically within the Services when delete features are utilized by a User with appropriate permissions.
SSLA EXHIBIT A.1
NOWSECURE STANDARD SERVICE & SUPPORT TIERS
| Core | Pro | Enterprise | |
| Service Features, Availability and SLA | |||
| NowSecure Platform for App TestingAccess to baseline, advanced and guided testing guided by industry standards. | ✓ | ✓ | ✓ |
| Platform AvailabilityPlatform engineered for 24x7x365 availability with negligible downtime for updates. | ✓ | ✓ | ✓ |
| Platform Monitoring24x7 Platform monitoring to ensure uptime, with online status portal and alerts. | ✓ | ✓ | ✓ |
| SLA Commitment99.5% availability commitment with SLA credits. | ✓ | ✓ | |
| Standard PoliciesFive test policy profiles including high risk, low risk, MASVS and financial. | ✓ | ✓ | ✓ |
| Customize PoliciesClone and customize or create totally custom test policies. | ✓ | ✓ | |
| Support Coverage | |||
| NowSecure Help CenterAccess to help center documentation and videos for self-service support, and the ability to submit a ticket via the support email. | ✓ | ✓ | ✓ |
| Live Product SupportSupport and troubleshooting assistance from the NowSecure team via phone/virtual call during standard U.S. business hours. | ✓ | ✓ | |
| Priority SupportPriority ticket routing for faster response to support tickets. | ✓ | ||
| Proactive Support and MonitoringProactive account monitoring and support ticket status reviews with CSM/TAM. | ✓ | ||
| Security, Risk and Legal | |||
| Enterprise SecuritySOC2 audited security assurance with security commitment. | ✓ | ✓ | ✓ |
| Role-Based Access Control (RBAC)Configurable RBAC and app groups for secure access control. | ✓ | ✓ | ✓ |
| Single Sign-On (SSO)Integrate to supported customer authentication provider. | ✓ | ✓ | |
| Comprehensive Platform Audit LogSecurity audit log of user logins and activities. | ✓ | ✓ | |
| Industry Standard Terms and ConditionsBalanced terms including IP indemnity, generally consistent with SaaS industry standards. | NowSecureTerms | NowSecureTerms with Amendment | Negotiated Terms |
| Core | Pro | Enterprise | |
| Product Onboarding | |||
| Self-Service Product Onboarding and Native Integration ImplementationAccess to video recordings and documentation for self-service onboarding. | ✓ | ✓ | ✓ |
| Standard Product Walkthrough During OnboardingVirtual live product overview and walkthrough during onboarding led by CSM/TAM. | ✓ | ✓ | |
| Native Integration ImplementationSupport for native integrations within NowSecure Platform by the NowSecure Support team. | ✓ | ✓ | |
| Non-Native Integration Implementations & API GuidanceExpert assistance of non-standard initial configurations of supported integrations. | ✓ | ||
| Dedicated Resources | |||
| Customer Success Manager (CSM)Primary point of contact at NowSecure. | ✓ | ✓ | |
| Technical Account Manager (TAM)Access to TAM support for escalation and advanced technical assistance. | ✓ (Team) | ✓ (Named) | |
| Executive SponsorshipAdvocacy from a NowSecure executive. | ✓ | ||
| Ongoing Partnership | |||
| Review of the NowSecure Product Roadmap | ✓ Annual | ✓ Quarterly | ✓ Quarterly+ |
| Review, Input, and Discussion with Product Team on Roadmap | ✓ | ||
| Monthly Touchpoints with Dedicated Resources | ✓ | ✓ | |
| Shared Slack ChannelSlack channel for collaboration between the NowSecure support team and customer. | ✓ | ||
| Product Training and Community | |||
| Monthly Tech Talks with Mobile AppSec ExpertsNowSecure discussions with experts on relevant mobile appsec topics. | ✓ | ✓ | ✓ |
| NowSecure Academy StandardAccess to NowSecure’s self-service mobile appsec and privacy courses and best practices for developers and security analysts. (Academy Premium content not included) | ✓ | ✓ | ✓ |
| NowSecure Product Training CoursesAccess to self-service onboarding training modules, tips, and resources for NowSecure product and services. | ✓ | ✓ | ✓ |
| Virtual Live Product Training and OnboardingVirtual live training and onboarding when requested. Must be scheduled in advance. | ✓ | ✓ | |
| Customized Virtual Live Training and OnboardingCustomized product training covering organization specific scenarios when requested. Must be scheduled in advance. | ✓ | ||
| Customer Advisory Board Membership (Optional)Optional membership to the NowSecure Customer Advisory Board (CAB). | ✓ | ||
| Core | Pro | Enterprise | |
| Add-On Resources | |||
| Authentication and Scripting Resource(If applicable) Authentication and scripting resource availability for multiple timezones (Advanced License only). Requires scoping/discussion, and must be on Enterprise tier. | optional add-on | ||
| Findings Reviews with NowSecure SMEsQuarterly findings reviews with NowSecure experts. Must be on the Enterprise tier. | optional add-on | ||
| NowSecure Academy (Premium Content) | optional add-on | optional add-on | optional add-on |
| Managed ServicesMust be on Pro or Enterprise tier. | optional add-on | optional add-on | |
ADDENDUM B
SUPPLEMENTAL SERVICES
This Supplemental Services Addendum governs the Supplemental Services to be provided to Customer by NowSecure, as identified in an Order Form. This Services Addendum incorporates the Terms and any capitalized terms not defined in this Services Addendum will have the meanings as set forth in the Terms. In the event of a conflict between the Terms and this Services Addendum, this Services Addendum shall prevail with respect to all Supplemental Services.
1. Supplemental Services. NowSecure will provide Customer with the Supplemental Services that are identified in an Order Form. Customer acknowledges and agrees that this Services Addendum only governs Supplemental Services.
2. Customer Policies. While performing Supplemental Services onsite at a Customer’s facility, NowSecure personnel will comply with all lawful workplace safety and security policies that Customer provides to NowSecure. Upon Customer’s written request, NowSecure will promptly replace any NowSecure personnel who fail to comply with such Customer policies.
3. Warranty. NowSecure represents and warrants that Supplemental Services will be provided to Customer in a manner consistent with the prevailing reasonable standard of care and skill ordinarily exercised by other providers under similar circumstances at the time of performance. Customer will notify NowSecure in writing of any warranty deficiencies within thirty (30) days of NowSecure performing the relevant Supplemental Service. Upon receipt of such notice, NowSecure will promptly attempt to re-perform the deficient Supplemental Service within thirty (30) days (or such longer period as agreed to by the parties in writing), or at NowSecure’s option, refund the Fees Customer paid for the deficient Supplemental Service. Such refund will be NowSecure’s entire liability to Customer in connection with the breach of the foregoing warranty. A Supplemental Service will be deemed accepted if no written notice of a warranty deficiency is received by NowSecure within thirty (30) days of delivery of the Supplemental Service.
4. Disclaimers. THE LIMITED WARRANTY PROVIDED IN SECTION 3 IS THE ONLY WARRANTY PROVIDED BY NOWSECURE IN CONNECTION WITH SUPPLEMENTAL SERVICES. THE PROVISIONS OF SECTION 8.4 (Disclaimers) IN THE TERMS ALSO APPLY TO SUPPLEMENTAL SERVICES.
5. Security Testing. Customer acknowledges the risks of service disruption and system modification inherent in certain types of security testing, including without limitation penetration testing, and that no security assessment is 100% accurate. Except to the extent caused by NowSecure’s gross negligence or willful misconduct, NowSecure shall have no liability to Customer, or any third party, for any service disruption, data corruption, system modification, or inaccurate finding or result, where Supplemental Services have been provided in accordance with prevailing industry standards and methodologies, and Customer instructions.
6. Customer Devices. Where applicable, Customer may furnish hardware related to certain Supplemental Services (“Customer Devices”). NowSecure will notify Customer of potential for damage in any procedure requested or required, or if any significant damage is discovered upon receipt or during performance of the Supplemental Services. NowSecure shall not be liable for any damage that may occur to Customer Devices during shipment or during NowSecure’s performance of authorized Supplemental Services. NowSecure will return all Customer Devices to Customer promptly after the completion of Supplemental Services.
7. Payment Terms. Customer agrees to pay all Fees for Supplemental Services as specified in the applicable Order Form. If specified in the Order Form or approved in writing, Customer shall pay out-of-pocket travel, hotel, and meal expenses reasonably incurred in connection with NowSecure’s delivery of the Supplemental Services (provided such expenses conform to Customer’s applicable written expense reimbursement policies and guidelines which Customer will provide to NowSecure in advance). Supplemental Services must be consumed within the period specified in the Order Form, or if not specified, within one (1) year from the date on the Order Form, after which Supplemental Services will expire and will be non-refundable. Customer may reschedule Supplemental Services by sending an email to [email protected], but if rescheduling results in NowSecure incurring unavoidable or additional expenses, such expenses shall be fully reimbursed by Customer.
8. Customer Responsibilities. Customer will provide hardware, software, facilities, materials, data, access, assistance, and cooperation reasonably necessary for NowSecure to perform Supplemental Services. Customer shall be responsible for ensuring it backs up and otherwise protects all data and software that is accessed or utilized by NowSecure. For Customer Devices, software, and data Customer provides to NowSecure (“Customer Materials”), Customer represents and warrants that it has the authority to provide, and authorize Supplemental Services to be performed, on such Customer Materials. Customer agrees to defend and hold harmless NowSecure in any Claim brought against NowSecure based on Customer’s failure to obtain authority contemplated in the preceding sentence, and to indemnify NowSecure from any damages, attorney fees, and costs finally awarded against NowSecure by a court of competent jurisdiction or included in a settlement approved by Customer in connection with such Claim. The indemnification requirements in Section 9.3 of the Terms apply to Customer’s indemnification obligations in this section.
9. Ownership. Customer owns and shall own all Customer Materials (including Customer Devices), as well as all Customer Reports. NowSecure shall use Customer Materials solely in connection with providing Customer with Supplemental Services. To the extent a Customer Report contains Pre-Existing Content, NowSecure grants Customer a license to such Pre-Existing Content in accordance with Section 2.2 of the Terms. Customer acknowledges that all standard training, configuration, support, and implementation materials are intended for Customer’s internal use only and may not be distributed externally without the prior written permission of NowSecure. NowSecure may configure software and train users, but NowSecure will not provide Customer any custom software development pursuant to this Supplemental Addendum or the Terms. In performing security assessments, NowSecure will apply preexisting tools and techniques in order to produce Customer Reports specific to Customer’s hardware or software, and will not create new ideas, processes, or inventions. Customer acknowledges and agrees that no transferrable intellectual property shall be created in connection with Supplemental Services.
10. No Solicitation or Employment. For a period of twelve (12) months following the expiration or termination of the Terms, Customer shall not hire, solicit or engage, directly or indirectly, any person who, at any time during the preceding twelve (12) months was an employee of NowSecure and performed Supplemental Services for Customer. If this restriction is violated NowSecure may seek injunction(s) from a court of competent jurisdiction.
11. Relationship. NowSecure personnel assigned to perform Supplemental Services hereunder are and shall remain personnel of NowSecure regardless of where Supplemental Services are performed and shall not for any purpose be considered Customer personnel or employees. Each party will be solely responsible for: (a) paying all wages and other compensation to its employees; (b) withholding and payment of federal and state individual income tax, Federal Insurance Contributions, Federal Unemployment Tax and other taxes and applicable amounts with respect to payments made to its employees; (c) providing all insurance and other employment related benefits to its employees; and (d) making any overtime payments to its employees if required by applicable law.
12. Personnel. Customer may at any time request replacement of any individual who is assigned to perform Supplemental Services for reasonable cause, and NowSecure shall promptly address such request. The parties may designate Key Personnel in an Order Form. “Key Personnel” means, for a particular Order Form, any member of NowSecure’s personnel specifically designated by name as key personnel essential to the performance of the Supplemental Services. If Customer requests any personnel replacement, or if an individual who is designated as Key Personnel under the governing Order Form leaves the employ of NowSecure or needs to be reassigned during the Supplemental Services delivery term, NowSecure will promptly designate a replacement and notify Customer. If Customer objects in good faith to the proposed replacement within seven (7) days after being notified thereof, NowSecure will propose an alternate replacement or otherwise address the objections, and the parties will endeavor to resolve them on a mutually agreeable basis.
13. Confidentiality. Each party shall be responsible for its employees’ and authorized representatives’ compliance with the confidentiality requirements in these Terms. Customer may request that NowSecure personnel assigned to provide Supplemental Services execute reasonable additional confidentiality agreements with Customer reflecting the confidentiality requirements herein.
14. Background Screening. With respect to any NowSecure personnel assigned to provide Supplemental Services, NowSecure will perform reasonable background screening to validate qualifications and trustworthiness including: (a) verify the identity of all NowSecure personnel in accordance with applicable law and industry standard practices; (b) use best efforts to obtain employment history for the past five (5) years through contacts with previous employers; (c) verify education if a specific certification is required for performance of Supplemental Services; and (d) conduct a criminal record check, covering all known counties of residence and employment during the preceding seven (7) year period.
ADDENDUM C
INFORMATION SECURITY
1. Security Program. In providing the Services, NowSecure shall implement the following security controls and practices in accordance with prevailing industry standards.
- Physical security. Physical security of all premises in which Customer Data will be processed and/or stored, including restricted access, physical barriers, visitor access control, and video monitoring.
- Access controls. Controls limiting access by role to personnel requiring access, using individual assigned credentials, only to the extent required to perform job functions (“least privilege”), with regular user access reviews (at least quarterly) and access logging and monitoring.
- Network Security. Network security program including (a) protection by means of firewalls with default deny, change control, and regular firewall configuration review (at least quarterly); (b) segregated VLANs/subnets, intrusion detection, and secure wi-fi configuration; and (c) internal and external vulnerability scanning (at least monthly), with regular patching of software including patching of any critical risk vulnerabilities within 72 hours and high risk vulnerabilities within 10 days.
- Data Security. Data security controls including (a) segregation of Customer Data; (b) use of strong and industry standard encryption for data-at-rest (AES-256 or successor) and data-in-transit (current TLS or successor).
- Personnel Security. Personnel security program including (a) screening including criminal background checks; (b) mandatory security awareness training, both upon hire and annual refresh; (c) formal onboarding and offboarding procedures including removal of access promptly (no more than 24 hours) upon termination or role change.
- Secure Development. Secure SDLC including (a) regular security training in accordance with role; (b) segregation of code development and code deployment, and segregation of production from development and QA/staging environments with production data restricted from use in development/testing; (c) secure code repository management with RBAC and change control; (d) secure code standards and practices, including regular code security analysis and code reviews; and (e) QA and security testing prior to production deployment.
- Supplier Security. Supplier security program to assess risk associated with new and existing suppliers, including sub-processors, to ensure any third-party supplier complies with security and confidentiality requirements.
- Audit and Assurance. Regular testing and auditing of controls including (a) annual third-party penetration testing; (b) regular review of policies and procedures (at least annual); and (c) appropriate corrective action and response plans.
2. Security Incident and Notification Obligations. In case of any Security Incident, defined as a security breach resulting in unauthorized or unlawful access, disclosure, destruction, loss, or alteration of or to Customer Data (including Personal Data, as defined in the DPA), upon becoming aware of the Security Incident NowSecure will promptly take action to contain, mitigate and remediate the Security Incident, and without undue delay (and in any event within 72 hours), notify Customer of the Security Incident with reasonable cause and impact information. NowSecure will provide reasonable assistance to Customer (and any law enforcement or regulatory official with proper jurisdiction) to fulfill Customer’s obligations under applicable law to investigate and respond to the Security Incident. Except as required by law, NowSecure will not notify the public, individuals, or regulatory authorities related to impacted Customer Data (including Personal Data) without Customer’s approval.
ADDENDUM D
DATA PROCESSING AGREEMENT
This Data Processing Agreement (“DPA”) supplements the agreement in place between Customer and NowSecure covering Customer’s use of NowSecure’s Services (the “Terms”). Unless otherwise defined in this DPA or in the Terms, all capitalized terms used in this DPA will have the meanings given to them in Section 9 of this DPA.
1. Scope and Term.
1.1. Roles of the Parties.
(a) Customer Personal Data. NowSecure will Process Customer Personal Data as Customer’s Processor in accordance with Customer’s instructions as outlined in Section 2.1 (Customer Instructions).
(b) NowSecure Account Data. NowSecure will Process NowSecure Account Data as a Controller for the following purposes:
(i) to provide and improve the Services;
(ii) to manage the Customer relationship (communicating with Customer in accordance with their account preferences, responding to Customer inquiries and providing technical support, etc.);
(iii) to facilitate security, fraud prevention, performance monitoring, business continuity and disaster recovery; and
(iv) to carry out core business functions such as accounting, billing, and filing taxes.
(c) NowSecure Usage Data. NowSecure will Process NowSecure Usage Data as a Controller for the following purposes:
(i) to provide, optimize, secure, and maintain NowSecure’s Services;
(ii) to optimize user experience; and
(iii) to inform NowSecure’s business strategy.
(d) Description of the Processing. Details regarding the Processing of Personal Data by NowSecure are stated in Schedule 1 (Description of Processing).
1.2. Term of the DPA. The term of this DPA coincides with the period of the Terms and terminates upon expiration or earlier termination of the Terms (or, if later, the date on which NowSecure ceases all Processing of Customer Personal Data).
1.3. Order of Precedence. If there is any conflict or inconsistency among the following documents, the order of precedence is: (1) the applicable terms stated in Schedule 2 (Region-Specific Terms including any transfer provisions); (2) the main body of this DPA; and (3) the Terms.
2. Processing of Personal Data.
2.1. Customer Instructions. NowSecure must Process Customer Personal Data in accordance with the documented lawful instructions of Customer as stated in the Terms (including this DPA) and respective Orders, as necessary to:
(a) enable the use of various features and functionalities in accordance with the Documentation (including as directed by users through the Hosted Services),
(b) provide Supplemental Services or
(c) comply with its legal obligations. NowSecure will notify Customer if it becomes aware, or reasonably believes, that Customer’s instructions violate Applicable Data Protection Law.
2.2. Confidentiality. NowSecure must treat Customer Personal Data as Customer’s Confidential Information under the Terms. NowSecure must ensure personnel authorized to Process Personal Data are bound by written or statutory obligations of confidentiality.
3. Security.
3.1. Security Measures. NowSecure has implemented and will maintain appropriate technical and organizational measures designed to protect the security, confidentiality, integrity, and availability of Customer Data and protect against Security Incidents. Customer is responsible for configuring the Services and using features and functionalities made available by NowSecure to maintain appropriate security in light of the nature of Customer Data. NowSecure’s current technical and organizational measures are described in Schedule 3. Customer acknowledges that the Security Measures are subject to technical progress and development and that NowSecure may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Hosted Services during a Subscription term.
3.2. Security Incidents. NowSecure must notify Customer without undue delay after becoming aware of a Security Incident. NowSecure must make reasonable efforts to identify the cause of the Security Incident, mitigate the effects and remediate the cause to the extent within NowSecure’s reasonable control. Upon Customer’s request and taking into account the nature of the Processing and the information available to NowSecure, NowSecure must assist Customer by providing information reasonably necessary for Customer to meet its Security Incident notification obligations under Applicable Data Protection Law. NowSecure’s notification of a Security Incident is not an acknowledgment by NowSecure of its fault or liability. Except as required by law, NowSecure will not release any notice regarding a Security Incident that identifies Customer without Customer’s approval, including to regulatory authorities, impacted individuals or the public
4. Sub-processing.
4.1. General Authorization. By entering into this DPA, Customer provides general authorization for NowSecure to engage Sub-processors to Process Customer Personal Data. NowSecure must:
(a) enter into a written agreement with each Sub-processor imposing data protection terms that require the Sub-processor to protect Customer Personal Data to the standard required by Applicable Data Protection Law and to the same standard provided by this DPA; and
(b) remain liable to Customer if such Sub-processor fails to fulfill its data protection obligations with regard to the relevant Processing activities under the Terms.
4.2. Sub-processors List. A list of the Sub-processors used by NowSecure is available in Schedule 4. Customer authorizes NowSecure to engage new Sub-processors not included in the list at the date of the execution of this DPA, whether as a replacement for an existing or as additional Sub-processors. NowSecure will inform Customer of the engagement of any new Sub-processor by updating the list of Sub-processors. If Customer reasonably believes that any new Sub-processor presents an unreasonable risk to Customer or prevents Customer from complying with Data Protection Laws, Customer may, within thirty (30) days of receiving such notice from NowSecure, object to the engagement of the new Sub-processor. If Customer reasonably objects to the engagement of a new Sub-processor, the parties will come together in good faith to discuss a resolution. NowSecure may choose to:
(a) not engage the new Sub-processor or
(b) take corrective steps as may be reasonably requested by Customer in its objection and use the new Sub-processor. If none of these options are reasonably possible and Customer continues to object for a legitimate reason, Customer may terminate the Terms and this DPA by written notice in accordance with this DPA in relation to those Services that involve the processing of Personal Data by the proposed new Sub-processor.
5. Assistance and Cooperation Obligations.
5.1. Data Subject Rights. Taking into account the nature of the Processing, NowSecure must provide reasonable and timely assistance to Customer to enable Customer to respond to requests for exercising a data subject’s rights (including rights of access, rectification, erasure, restriction, objection, and data portability) in respect to Customer personal data.
5.2. Cooperation Obligations. Upon Customer’s reasonable request, and taking into account the nature of the applicable Processing, NowSecure will provide reasonable assistance to Customer in fulfilling Customer’s obligations under Applicable Data Protection Law (including data protection impact assessments and consultations with regulatory authorities), provided that Customer cannot reasonably fulfill such obligations independently with help of available Documentation.
5.3. Third Party Requests. Unless prohibited by law, NowSecure will promptly notify Customer of any valid, enforceable subpoena, warrant, or court order from law enforcement or public authorities compelling NowSecure to disclose Customer Personal Data. In the event that NowSecure receives an inquiry or a request for information from any other third party (such as a regulator or data subject) concerning the Processing of Customer Personal Data, NowSecure will redirect such inquiries to Customer, and will not provide any information unless required to do so under applicable Law.
6. Deletion and Return of Customer Personal Data.
6.1. During Subscription Term. During the Subscription term, Customer may, through the features of the Hosted Services, access, retrieve or delete Customer Personal Data.
6.2. Post Termination. Following expiration or termination of the Terms, NowSecure must, in accordance with the Documentation, delete all Customer Personal Data. Notwithstanding the foregoing, NowSecure may retain Customer Personal Data:
(a) as required by Applicable Data Protection Law or
(b) in accordance with its standard backup or record retention policies, provided that, in either case, NowSecure will maintain the confidentiality of, and otherwise comply with the applicable provisions of this DPA with respect to retained Customer Personal Data and not further Process it except as required by Applicable Data Protection Law.
7. Audit.
7.1. Audit Reports. NowSecure is regularly audited by independent third-party auditors and/or internal auditors. Upon request, and on the condition that Customer has entered into an applicable non-disclosure agreement with NowSecure, NowSecure will supply a summary copy of relevant audit report(s) (“Report”) to Customer, so Customer can verify NowSecure’s compliance with the audit standards against which it has been assessed, and this DPA. If Customer cannot reasonably verify NowSecure’s compliance with the terms of this DPA, NowSecure will provide written responses (on a confidential basis) to all reasonable requests for information made by Customer related to its Processing of Customer Personal Data, provided that such right may only be exercised no more than once every twelve (12) months.
7.2. On-site Audits. Only to the extent Customer cannot reasonably satisfy NowSecure’s compliance with this DPA through the exercise of its rights under Section 7.1 above, or where required by Applicable Data Protection Law or a regulatory authority, Customer, or its authorized representatives, may, at Customer’s expense, conduct audits (including inspections) during the term of the Terms to assess NowSecure’s compliance with the terms of this DPA. Any audit must:
(a) be conducted during NowSecure’s regular business hours, with reasonable advance written notice of at least thirty (30) calendar days (unless Applicable Data Protection Law or a regulatory authority requires a shorter notice period);
(b) be subject to reasonable confidentiality controls obligating Customer (and its authorized representatives) to keep confidential any information disclosed that, by its nature, should be confidential;
(c) occur no more than once every twelve (12) months; and
(d) restrict its findings to only information relevant to Customer.
8. International Provisions. To the extent NowSecure Processes Personal Data protected by Applicable Data Protection Laws in one of the regions listed in Schedule 2 (Region-Specific Terms), the terms specified for the applicable regions will also apply, including the provisions relevant for international transfers of Personal Data (directly or via onward transfer).
9. Definitions.
“Applicable Data Protection Law” means all Laws applicable to the Processing of Personal Data under the Terms.
“NowSecure Account Data” means Personal Data relating to Customer’s relationship with NowSecure, including:
(a) users’ account information (e.g. name, email address, or NowSecure’s account ID);
(b) billing and contact information of individual(s) associated with Customer’s NowSecure account (e.g. billing address, email address, or name);
(c) users’ device and connection information (e.g. IP address); and
(d) content/description of technical support requests (excluding attachments).
“NowSecure Usage Data” means Personal Data relating to or obtained in connection with the use, performance, operation, or support of the Services. NowSecure Usage Data may include event name (i.e. what action Users performed), event timestamps, browser information, and diagnostic data. For clarity, NowSecure Usage Data does not include Customer Personal Data.
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
“Customer Personal Data” means Personal Data contained in Customer Data and/or Customer materials that NowSecure Processes under the Terms solely on behalf of Customer.
“Personal Data” means information about an identified or identifiable natural person, or which otherwise constitutes “personal data”, “personal information”, “personally identifiable information” or similar terms as defined in Applicable Data Protection Law.
“Processing” (and “Process”) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Processor” means the entity which Processes Personal Data on behalf of the Controller.
“Security Incident” means a security breach resulting in unauthorized or unlawful access, disclosure, destruction, loss, or alteration of or to Customer Data, as further described in Addendum C (Information Security); provided that, with respect to Personal Data, Security Incident means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data Processed by NowSecure and/or its Sub-processors.
“Sub-processor” means any third party (including NowSecure Affiliates) engaged by NowSecure to Process Customer Personal Data.
Schedule 1
Description of Processing
1. Categories of data subjects whose Personal Data is Processed: Customer users (employees, contractors)
2. Categories of Personal Data Processed: General personal data, including name, contact info and online identifiers
3. Sensitive data transferred: Customer Personal Data, NowSecure Account Data and Customer usage data will not contain special categories of personal data (“Sensitive Data”) such as:
(a) racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership,
(b) genetic data, biometric data Processed for the purposes of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, or
(c) relating to criminal convictions and offences.
4. The frequency of the transfer: Continuous.
5. Nature of the Processing: NowSecure will Process Personal Data in order to provide the Services in accordance with the Terms, including this DPA. Additional information regarding the nature of the Processing (including transfer) is described in respective Orders for relevant Services and Documentation referring to technical capabilities and features, including but not limited to collection, structuring, storage, transmission, or otherwise making available of Personal Data by automated means.
6. Purpose(s) of the Processing:
6.1. Customer Personal Data: NowSecure will Process Customer Personal Data as Processor in accordance with Customer’s instructions as set out in Section 2.1 (Customer Instructions).
6.2. NowSecure Account Data and NowSecure Usage Data: NowSecure will Process NowSecure Account Data and NowSecure Usage Data for the limited and specified purposes outlined in Section 1.1 (Roles of the Parties).
7. Duration of Processing:
7.1. Customer Personal Data: NowSecure will Process Customer Personal Data for the term of the Terms as outlined in Section 6 (Deletion and Return of Customer Personal Data).
7.2. NowSecure Account Data and NowSecure Usage Data: NowSecure will Process NowSecure Account Data and NowSecure Usage Data only as long as required:
(a) to provide Services and to Customer in accordance with the Terms;
(b) for NowSecure’s legitimate business purposes outlined in Section 1.1 (Roles of the Parties); or
(c) by applicable law(s).
8. Transfers to (Sub-)processors: NowSecure will transfer Customer Personal Data to Sub-processors as permitted in Section 4 (Sub-processing).
Schedule 2
Region-Specific Terms
Unless otherwise defined in this DPA or in the Terms, all capitalized terms used in this Schedule will have the meanings given to them in Section 9 of the DPA and Section 4 of this Schedule, as applicable.
1. Europe, United Kingdom and Switzerland.
1.1. Customer Instructions. In addition to Section 2.1 (Customer Instructions) of the DPA above, NowSecure will Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of such Customer Personal Data to a third country or an international organization, unless required to do so by Applicable Data Protection Law to which NowSecure is subject; in such a case, NowSecure shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. NowSecure will promptly inform Customer if it becomes aware that Customer’s Processing instructions infringe Applicable Data Protection Law.
1.2. European Transfers. Where Personal Data protected by the EU Data Protection Law is transferred, either directly or via onward transfer, to a country outside of Europe that is not subject to an adequacy decision, the following applies:
(a) The EU SCCs are hereby incorporated into this DPA by reference as follows:
(i) Customer is the “data exporter” and NowSecure is the “data importer”.
(ii) Module One (Controller to Controller) applies where NowSecure is Processing NowSecure Account Data or NowSecure Usage Data.
(iii) Module Two (Controller to Processor) applies where Customer is a Controller of Customer Personal Data and NowSecure is Processing Customer Personal Data as a Processor.
(iv) Module Three (Processor to Processor) applies where Customer is a Processor of Customer Personal Data and NowSecure is Processing Customer Personal Data as another Processor.
(v) By entering into this DPA, each party is deemed to have signed the EU SCCs as of the commencement date of the Terms.
(b) For each Module, where applicable:
(i) In Clause 7, the optional docking clause does not apply.
(ii) In Clause 9, Option 2 applies, and the time period for prior notice of Sub-processor changes is stated in Section 4 (Sub-processing) of this DPA.
(iii) In Clause 11, the optional language does not apply.
(iv) In Clause 17, Option 1 applies, and the EU SCCs are governed by Irish law.
(v) In Clause 18(b), disputes will be resolved before the courts of Ireland.
(vi) The Appendix of EU SCCs is populated as follows:
• The information required for Annex I(A) is located in the Terms and/or relevant Orders.
• The information required for Annex I(B) is located in Schedule 1 (Description of Processing) of this DPA.
• The competent supervisory authority in Annex I(C) will be determined in accordance with the Applicable Data Protection Law; and
• The information required for Annex II is located in Schedule 3.
1.3. Swiss Transfers. Where Personal Data protected by the Swiss FADP is transferred, either directly or via onward transfer, to any other country that is not subject to an adequacy decision, the EU SCCs apply as stated in Section 1.2 (European Transfers) above with the following modifications:
(a) All references in the EU SCCs to “Regulation (EU) 2016/679” will be interpreted as references to the Swiss FADP, and references to specific Articles of “Regulation (EU) 2016/679” will be replaced with the equivalent article or section of the Swiss FADP; all references to the EU Data Protection Law in this DPA will be interpreted as references to the FADP.
(b) In Clause 13, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
(c) In Clause 17, the EU SCCs are governed by the laws of Switzerland.
(d) In Clause 18(b), disputes will be resolved before the courts of Switzerland.
(e) All references to Member State will be interpreted to include Switzerland and Data Subjects in Switzerland are not excluded from enforcing their rights in their place of habitual residence in accordance with Clause 18(c).
1.4. United Kingdom Transfers. Where Personal Data protected by the UK Data Protection Law is transferred, either directly or via onward transfer, to a country outside of the United Kingdom that is not subject to an adequacy decision, the following applies:
(a) The EU SCCs apply as set forth in Section 1.2 (European Transfers) above with the following modifications:
(i) Each party shall be deemed to have signed the UK Addendum.
(ii) For Table 1 of the UK Addendum, the parties’ key contact information is located in the Terms and/or relevant Orders.
(iii) For Table 2 of the UK Addendum, the relevant information about the version of the EU SCCs, modules, and selected clauses which this UK Addendum is appended to is located above in Section 1.2 (European Transfers) of this Schedule.
(iv) For Table 3 of the UK Addendum:
• The information required for Annex 1A is located in the Terms and/or relevant Orders.
• The Information required for Annex 1B is located in Schedule 1 (Description of Processing) of this DPA.
• The information required for Annex II is located in Schedule 3; and
• The information required for Annex III is located in Section 4 (Sub-processing) of this DPA.
(b) In Table 4 of the UK Addendum, both the data importer and data exporter may end the UK Addendum.
1.5. Data Privacy Framework. NowSecure adheres to the Data Privacy Framework. As required by the Data Privacy Framework, NowSecure:
(a) provides at least the same level of privacy protection as is required by the Data Privacy Framework Principles;
(b) will notify Customer if NowSecure makes a determination it can no longer meet its obligation to provide the same level of protection as is required by the Data Privacy Framework Principles, and
(c) will, upon written notice, take reasonable and appropriate steps to remediate any unauthorized Processing of Personal Data.
2. United States of America. The following terms apply where NowSecure Processes Personal Data subject to the US State Privacy Laws:
2.1. To the extent Customer Personal Data includes personal information protected under US State Privacy Laws that NowSecure Processes as a Service Provider or Processor, on behalf of Customer, NowSecure will Process such Customer Personal Data in accordance with the US State Privacy Laws, including by complying with applicable sections of the US State Privacy Laws and providing the same level of privacy protection as required by US State Privacy Laws, and in accordance with Customer’s written instructions, as necessary for the limited and specified purposes identified in Section 1.1(a) (Customer Personal Data) and Schedule 1 (Description of Processing) of this DPA. NowSecure will not:
(a) retain, use, disclose or otherwise Process such Customer Personal Data for a commercial purpose other than for the limited and specified purposes identified in this DPA, the Terms, and/or any related Order, or as otherwise permitted under US State Privacy Laws;
(b) “sell” or “share” such Customer Personal Data within the meaning of the US State Privacy Laws; and
(c) retain, use, disclose or otherwise Process such Customer Personal Data outside the direct business relationship with Customer and not combine such Customer Personal Data with personal information that it receives from other sources, except as permitted under US State Privacy Laws.
2.2. NowSecure must inform Customer if it determines that it can no longer meet its obligations under US State Privacy Laws within the timeframe specified by such laws, in which case Customer may take reasonable and appropriate steps to prevent, stop, or remediate any unauthorized Processing of such Customer Personal Data.
2.3. To the extent Customer discloses or otherwise makes available Deidentified Data to NowSecure or to the extent NowSecure creates Deidentified Data from Customer Personal Data, in each case in its capacity as a Service Provider, NowSecure will:
(a) adopt reasonable measures to prevent such Deidentified Data from being used to infer information about, or otherwise being linked to, a particular natural person or household;
(b) publicly commit to maintain and use such Deidentified Data in a de-identified form and to not attempt to re-identify the Deidentified Data, except that NowSecure may attempt to re-identify such data solely for the purpose of determining whether its de-identification processes are compliant with the US State Privacy Laws; and
(c) before sharing Deidentified Data with any other party, including Sub-processors, contractors, or any other persons (“Recipients”), contractually obligate any such Recipients to comply with all requirements of this Section 2.3 (including imposing this requirement on any further Recipients).
3. South Korea.
3.1. Customer agrees that it has provided notice and obtained all consents and rights necessary under Applicable Data Protection Law for NowSecure to Process NowSecure Account Data and NowSecure Usage Data pursuant to the Terms (including this DPA).
3.2. To the extent Customer discloses or otherwise makes available Deidentified Data to NowSecure, NowSecure will:
(a) maintain and use such Deidentified Data in a de-identified form and not attempt to re-identify the Deidentified Data; and
(b) before sharing Deidentified Data with any other party, including Sub-processors, contractors, or any other persons (“Recipients”), contractually obligate any such Recipients to comply with all requirements of this Section 3.2 (including imposing this requirement on any further Recipients).
4. Definitions.
4.1. Where Personal Data is subject to the laws of one the following regions, the definition of “Applicable Data Protection Law” includes:
(a) Australia: the Australian Privacy Act;
(b) Brazil: the Brazilian Lei Geral de Proteção de Dados (General Personal Data Protection Act);
(c) Canada: the Canadian Personal Information Protection and Electronic Documents Act;
(d) Europe: (i) the Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data (General Data Protection Regulation, or GDPR) and (ii) the EU e-Privacy Directive (Directive 2002/58/EC) as amended, superseded or replaced from time to time (“EU Data Protection Law”);
(e) Japan: the Japanese Act on the Protection of Personal Information;
(f) Singapore: the Singapore Personal Data Protection Act;
(g) South Korea: the South Korean Personal Information Protection Act (“PIPA”) and the Enforcement Decrees of PIPA;
(h) Switzerland: the Swiss Federal Act on Data Protection and its implementing regulations as amended, superseded, or replaced from time to time (“Swiss FADP”);
(i) The United Kingdom: the Data Protection Act 2018 and the GDPR as saved into United Kingdom law by virtue of Section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 as amended, superseded or replaced from time to time (“UK Data Protection Law”); and
(j) The United States: all state laws relating to the protection and Processing of Personal Data in effect in the United States of America, which may include, without limitation, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and the Utah Consumer Privacy Act (“US State Privacy Laws”).
4.2. “Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, a data subject.
4.3. “Data Privacy Framework” means the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework self-certification program operated by the US Department of Commerce.
4.4. “Europe” includes, for the purposes of this DPA, the Member States of the European Union and European Economic Area.
4.5. “EU SCCs” means the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time.
4.6. “Service Provider” has the same meaning as given in the CCPA.
4.7. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time.
Schedule 3
Technical & Organizational Measures
NowSecure has implemented the following administrative, physical, technical, and organizational security measures, at a minimum, to protect all Personal Data Processed under this DPA:
| Subject Matter | Measures |
| Organization of Information Security | NowSecure will maintain the following (or materially equivalent) organizational security controls: a. Information security awareness training is provided to all employees. The training includes an acknowledgement of and commitment to the NowSecure Information Security Policy. Additional security training (e.g., secure development practices) is also required for certain job roles.b. Employees with access to confidential data are hired under organizational procedures, including a detailed application form, background verification (where allowed by law), and agreement to confidentiality terms.c. All company employees are required to comply with the NowSecure Code of Business Conduct.d. Regular internal and external independent assessments are conducted to identify potential areas of improvement. |
| Security Program | a. Security Program. NowSecure maintains a security program that establishes processes and safeguards designed to maintain security at an appropriate level.b. Industry Standards. NowSecure’s security program is designed based on relevant industry standards, presently including but not limited to ISO 27001 and NIST recommended practices.c. Information Security Policy. NowSecure maintains a written, enterprise-wide Information Security Policy designed to protect the confidentiality, integrity, and availability of Customer Data. The Information Security Policy establishes written standards and guidelines regarding information security in NowSecure’s operations and the conduct of its personnel, including those relating to acceptable use, access control, authentication, device security, security monitoring, supplier security management, and incident management, among others. |
| Physical Security Controls | Physical access to NowSecure facilities is controlled by the use of a card access or other equivalent system that provides reasonable assurance that access is limited to authorized individuals. Visitor access is restricted, and physical security measures are regularly assessed. |
| Business Continuity Planning | NowSecure maintains a master Business Continuity and Disaster Recovery (BC/DR) plan and corresponding recovery and restoration procedures designed to maintain availability in accordance with NowSecure’s customer SLA commitments, and restore service promptly in case of interruption. NowSecure provides availability and health information at NowSecure’s status dashboard. |
| Authentication | NowSecure maintains policies and standards for accounts and passwords to protect user information. Industry-standard cryptographically strong hashing algorithms are implemented prior to storing user passwords or credentials. |
| Encryption | NowSecure maintains a Cryptographic Controls Policy and enforces industry standard encryption algorithms to secure data in transit and data at rest, using encryption keys from trusted enterprise providers. |
Schedule 4
Sub-processor Information
Group A: SaaS Sub-processors
Processing personal data provided by Customer to the NowSecure Platform, including the related product support portal and training features. Platform includes Mobile App Risk Intel (MARI) products.
| Sub-processor | Service(s) | Purpose | Location (Country) |
| Amazon Web Services, Inc. | Platform | IaaS (Infrastructure as a service) and PaaS (Platform as a Service) | USA |
| Okta, Inc. (formerly Auth0) | Platform, Academy, Support | User authentication, Single Sign-on | USA |
| Cloudflare, Inc. | Platform | Network security and delivery | USA |
| Pendo.io, Inc. | Platform | User experience measurement and engagement | USA |
| Rill Data, Inc. | Platform | Internal Analytics | USA |
| Skilljar, Inc. | Academy | User onboarding & training | USA |
| Zendesk, Inc. | Support | Hosted helpdesk system | USA |
Group B: Non-US Support
Only for customers located outside the U.S. or who request / authorize non-U.S. based support resources, the following entities may be used.
| Sub-processor | Service(s) | Purpose | Location (Country) |
| NowSecure Ltd. | Platform, Support | Product onboarding, support and troubleshooting | UK |
| Bloop, LLC | Platform, Support | Product onboarding, support and troubleshooting | Philippines |