PickFu

DATA SECURITY ADDENDUM

1. Definitions.

a. "Client Data" means any Client information or data pertaining to Client or its employees, clients or their guests/users that has not also been provided to the Company by one or more of its other customers, clients or partners and is Processed in fulfillment of the obligations under the Agreement or any Order Form.

b. "Information Systems" means any systems, processes, applications, and network elements, solely controlled by the Company and used to Process Data in fulfillment of the Company's obligations under this Agreement.

c. "Process," "Processing" or "Processed" means any receipt, use, access, disposal, storage, distribution, transmission or any other use of Data ("Processing").

2. Information Security.

a. The Company shall implement and maintain security safeguards, including administrative, physical and technical safeguards (including safeguards against viruses, worms, trojan horses and other disabling or damaging codes) that are designed to prevent the unauthorized, collection, access, use, disclosure, or accidental or deliberate loss or destruction of the Client Data, and exercise at least the same degree of care to safeguard Client Data that the Company would exercise to protect its own property of a similar nature.

b. All data centers where Client Data is residing must have SSAE16 SOC2, ISO27001 or an industry standard information security certification. Copies of the audit report summaries must be made available to Client upon request. Copies of the audit reports in detail must be made available in the event of a confirmed Security Incident (defined below).

c. The Company shall use up-to-date virus detection software to detect the presence of any viruses and eradicate the same prior to the provision of Services to Client. The Company agrees to notify Client within forty-eight (48) hours upon discovery of any virus, key stroke loggers, or any similar item or code that is incorporated into the Information Systems used to provide the Services and, if Client discovers or reasonably suspects any virus, key stroke loggers, or any similar item or code to be present in such Information Systems, the Company agrees to take prompt action, at its own expense, to identify, preserve evidence, eradicate, and to carry out any recovery necessary to remedy the impact of such virus, key stroke loggers, or similar items or code.

3. Self-Certification. The Company shall:

a. Ensure that all personnel, subcontractors or representatives performing work or otherwise Processing any of the Data covered under this Agreement are informed and are in compliance with the Company’s security policies.

b. Retain complete and accurate records relating to its performance of its obligations under this Exhibit in a format that will permit audit for a period of no less than one (1) year, or longer as may be required pursuant to a court order or civil or regulatory proceeding. Notwithstanding the foregoing, the Company shall only be required to maintain security logs for a minimum of three (3) months.

4. Right to Audit. The Company shall reasonably cooperate with Client’s efforts to verify the Company’s compliance with this Exhibit through the completion by the Company of such questionnaires as Client may reasonably require. The Company will provide a commitment to Client within thirty (30) days of any security issues discovered by Client to address such issues in a timely manner. The Company shall also participate, at its sole expense, in all regulatory inquiries or investigations relating to this Agreement, as reasonably requested by Client.

5. System Testing. Vulnerability assessment scanning must be performed for Information Systems using industry accepted toolsets, including without limitation Openvas "Open Vulnerability Assessment Scanner", OWASP ZAP "Open Web Application Security Project" and Qulays SSL Labs Server Test, and shall occur on a quarterly basis. Penetration test must be performed for Information Systems on an annual basis. Any vulnerability Assessments resulting in findings that are critical or high must be reported to Client within five (5) business days. Included in this report must be an explanation of the findings and the plan for mitigation of the findings. In the event the mitigation plans leave unacceptable risks to the Data, as determined by Client, Client reserves the right to terminate this Agreement for cause.

6. Security Incidents. The Company shall report to Client any Processing of covered Data not authorized by this Agreement or in writing by Client including, without limitation, any reasonable belief than an unauthorized individual has accessed, used or otherwise Processed Client Data ("Security Incident"). The Company shall make the report to Client promptly upon discovery of the Security Incident but in no event more than forty-eight (48) hours after the Company becomes aware of such Security Incident. In connection with a Security Incident, the Company shall:

a. Take immediate action, at its own expense, to investigate the Security Incident,

b. Identify and mitigate the effects, and to carry out any recovery or other action necessary to remedy the Security Incident.

c. Provide Client with a detailed description of the Security Incident and any other information that may be reasonably requested concerning the details of the incident as soon as the information becomes available. Regular status updates will occur at mutually agreed intervals for the duration of the incident, and within five (5) days of the closure of the incident, the Company shall provide a written report describing the incident, corrective actions and plans for future actions to prevent a similar incident.

d. Provide Client with notification as to the content prior to the release of any communications, notices, press releases, or reports related to any Security Incident and specifically referring to Client Information Systems and/or Client Data in connection with any publication or public communication thereof to any third party.

e. Client Data. To the extent that the Company uses, accesses, maintains, discloses or shares any Client Data in connection with Services, the Company shall do so only for the benefit of Client, as instructed by Client, and only to the extent strictly necessary to perform its obligations under this Agreement, any Order Form or as otherwise required by law.

7. Within sixty (60) days after termination of this Agreement (or as otherwise set forth in an Order Form), the Company shall, at Client’s discretion, return or destroy all Client Data residing in databases, transaction logs, exported files or backup copies, and upon the completion thereof provide Client with a written certification signed by an officer of the Company. Notwithstanding the foregoing, the Company may retain such Client Data pursuant to its standard archiving practices. Each Party represents and warrants to the other Party that it has in place procedures to address data subject rights to access to, deletion and rectification of personal data under applicable laws and regulations, and will provide the other Party with reasonable assistance in responding to requests from data subjects and regulatory authorities.