Loading...
HomeMy WebLinkAbout2022-077-E-IT Dept-PUBLIC LIBRARY ASSOCIATION, a divison of the American Library Association-Digital learning DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 [Departmental Use Only] TITLE FY NORTH CAROLINA SERVICES AGREEMENT NO RFP/RFQ ORANGE COUNTY This Services Agreement (hereinafter "Agreement"), made and entered into this 15 day of February, 2022, ("Effective Date") by and between Orange County, North Carolina a political subdivision of the State of North Carolina (hereinafter, the "County") and the American Library Association, an Illinois not-for-profit corporation, acting by and through its Public Library Association Division, 50 E. Huron St., Chicago, IL 60611, (hereinafter, the "Provider"). WITNESSETH: That the County and Provider,for the consideration herein named,do hereby agree as follows: 1. Services a. Scope of Work. i) This Agreement is for services to be rendered by Provider to County with respect to (insert type of project): DigitalLearn.org is an online resource which builds upon and fosters the work of libraries and community organizations as they work to increase digital literacy across the nation. Included in DigitalLearn.org is a collection of self- directed tutorials for end-users to increase digital literacy, as well as a community of practice for public library-based digital literacy trainers to share resources, tools and best practices. CKD Technology Partners serves as a subcontractor for the Provider in maintaining the DigitalLearn platform. ii) By executing this Agreement, the Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner. iii) Time is of the essence with respect to this Agreement. iv) The services to be performed under this Agreement consist of Basic Services, as described and designated in Section 3 hereof. Compensation to the Provider for Basic Services under this Agreement shall be as set forth herein. 2. Responsibilities of the Provider a. Services to be provided. The Provider shall provide the County with all services required in Section 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. b. Standard of Care. Revised 06/21 012822 1 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 i) The Provider shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Provider practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Provider is solely responsible for the professional quality, accuracy and timely completion and submission of all work related to the Basic Services. ii) Provider shall be responsible for all errors or omissions of its agents, contractors, employees, or assigns in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. iii) The Provider shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. iv) Provider is an independent contractor of County. Any and all employees of the Provider engaged by the Provider in the performance of any work or services required of the Provider under this Agreement, shall be considered employees or agents of the Provider only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Provider. v) If activities related to the performance of this Agreement require specific licenses, certifications, or related credentials Provider represents that it or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. vi) In determining the Basic Services to be provided, should any documents be referenced in this Agreement,the terms of this Agreement shall have priority in any conflict between the terms of referenced documents and the terms of this Agreement. vii) Should this Agreement involve project designs, the construction or creation of which is to be bid out or fulfilled by other contractors, and bidding or negotiation with contractors produce prices which, when added to the other elements of the approved total project cost, produce a cost that is in excess of the approved total project cost,the Provider shall participate with the County in negotiation and design adjustments to the extent such are necessary to obtain prices within the approved total project cost. All activity of the Provider with respect to these matters shall constitute Basic Services and shall be performed by the Provider without additional compensation. If negotiation and design adjustments fail to bring costs within the total project cost the County may reject all bids and Provider will redesign or reduce portions of the project in an effort to reduce the bid prices to within the total project cost and rebid the project. One such redesign is included within Basic Services. If Revised 06/21 012822 2 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 this second letting for bids does not produce bids that are within the approved total project cost initially or after negotiations with the contractor the cost is not reduced to an amount within the total project cost, the Provider is not obligated to engage in further redesign. 3. Basic Services a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows (fully describe services to be provided): Refer to (i) Attachment A - DigitalLearn - Agreement for Services, (ii) Attachment B- DigitalLearn - Cloud Questionnaire, (iii) Attachment C - DigitalLearn - Cyber Liability Questionnaire_Digital Learning Cyber Policy, (iv)Attachment D-DigitalLearn-Building Your Own DigitalLearn Site Handout 2021 4. Duration of Services a. Term. The term of this Agreement shall be from February 1, 2021 to June 30, 2023 b. Scheduling of Services. i) The Provider shall schedule and perform its activities in a timely manner. ii) Should the County determine that the Provider is behind schedule, it may require the Provider to expedite and accelerate its efforts, including providing additional resources and working overtime,as necessary,to perform its services in accordance with the approved project schedule at no additional cost to the County. iii) The Commencement Date for the Provider's Basic Services shall be 2/15/2022. 5. Compensation a. Compensation for Basic Services. Compensation for Basic Services shall include all compensation due the Provider from the County for all services satisfactorily (as determined by the County)performed pursuant to this Agreement. The maximum amount payable for Basic Services shall not exceed fifteen thousand Dollars ($15,000.00). Payment for satisfactorily performed Basic Services shall become due and payable within thirty (30) days of Provider properly invoicing County. Payment shall be subject to provisions of Section 5(b). b. Disputes. In the event the amount stated on an invoice is disputed by the County, the County may withhold payment of all or a portion of the amount stated on an invoice until the parties resolve the dispute. Should Provider fail to perform its duties under the terms of this Agreement,County may,without fault or penalty,withhold any payment associated with the work to be performed until such time as said work is completed. c. Additional Services. County shall not be responsible for costs related to any services in addition to the Basic Services performed by Provider unless County requests such additional services in writing and such additional services are evidenced by a written amendment to this Agreement. Revised 06/21 012822 3 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 6. Responsibilities of the County a. Cooperation and Coordination. The County has designated (Erin Sapienza) to act as the County's representative with respect to the Project who shall have the authority to render decisions within guidelines established by the County Manager or the County Board of Commissioners and who shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. 7. Insurance a. General Requirements. Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers' Compensation Insurance, and any additional insurance as may be required by County's Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing division/contracts.php). If County's Risk Manager determines additional insurance coverage is required such additional insurance shall consist of N/A (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 8. Indemnity a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without limitation, to defend, indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Provider except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Provider to indemnify the County to the fullest extent permitted under North Carolina law. 9. Amendments to the Agreement a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Provider. The Provider shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. 10. Termination a. Termination for Convenience of the County. This Agreement may be terminated without cause by the County and for its convenience upon seven (7) days' prior written notice to the Provider. b. Other Termination. The Provider may terminate this Agreement based upon the County's Revised 06/21 012822 4 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 material breach of this Agreement; provided, the County has not taken all reasonable actions to remedy the breach. The Provider shall give the County seven (7) days'prior written notice of its intent to terminate this Agreement for cause. Either party may terminate this Agreement upon notice to the other party that obligations pursuant to this Agreement are made impractical due to declarations of emergency by Orange County or by North Carolina due to events directly impacting Orange County. Both parties shall remain responsible for all payment and performance due up to the receipt of such notice, but shall have no further obligation or responsibility beyond that date provided the terminating party has taken all reasonable steps to complete the performance of its obligations. c. Compensation After Termination. i) In the event of termination, the Provider shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Provider. Upon request of the County, the Provider shall submit to County all relevant documentation, including but not limited to,job cost records, to support its claims for final compensation. ii) Should this Agreement be terminated, the Provider shall deliver to the County within seven(7)days, at no additional cost, all deliverables including any electronic data or files relating to the Project. d. Waiver. The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Provider with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. e. Suspension. County may suspend the Basic Services and this Agreement at any time for County's convenience and without penalty to County upon three (3) days' notice to Provider. Upon any suspension by County, Provider shall discontinue work on the Basic Services and shall not resume the Basic Services until notified to proceed by County. 11. Additional Provisions a. Limitation and Assignment. The County and the Provider each bind themselves, their successors, assigns and legal representatives to the terms of this Agreement. Neither the County nor the Provider shall assign or transfer its interest in this Agreement without the written consent of the other. b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. By executing this Agreement Provider affirms that Provider and any subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to Revised 06/21 012822 5 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.81. c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal non-discrimination laws, policies, rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is incorporated herein by reference and may be viewed at hqp://www.oran eg countync. og v/departments/purchasing division/contracts.php.) Any violation of the Orange County Non-Discrimination Policy is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. e. Entire Agreement. This Agreement represents the entire and integrated agreement between the County and the Provider and supersedes all prior negotiations,representations or agreements, either written or oral. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. f. Severability. If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. g. Ownership of Work Product. Should Provider's performance of this Agreement generate documents, items or things that are specific to this Project such documents,items or things shall become the property of the County and may be used on any other project without additional compensation to the Provider. The use of the documents,items or things by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable or not appropriated for the performance of County's obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Provider of the unavailability or non-appropriation of public funds.It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the Revised 06/21 012822 6 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 requirements of this Agreement. In the event of a change in the County's statutory authority, mandate or mandated functions, by state or federal legislative or regulatory action, which adversely affects County's authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Provider of such limitation or change in County's legal authority. i. Si natures. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. j. Notices. Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Provider's Name Attention:Erin Sapienza Attention:MaryDavisFournier Public Library Association, a division of the American Library Association P.O. Box 8181 225 N Michigan Ave,Ste 1300 Hillsborough,NC 27278 Chicago, IL 60601 [SIGNATURE PAGE TO FOLLOW] Revised 06/21 012822 _ 7 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. ORANGE COUNTY: PROVIDER: DocuSigned by: DocuSigned by: L 50i.t,�.�c2/15/20222/15/2022 By: E 1-DFP.BP.BZ483 By. Mary Davis Fournier Executive Director, Public Library Association Printed Name and Title DocuSigned by: By: -Q- Y°u 2/15/2022 1 D07F8EF4B8148E... Tracie D. Hall, Executive Director, American Library Association Printed Name and Title Revised 06/21 012822 _ 8 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 ORANGE COUNTY—DEPARTMENT USE ONLY Party/Vendor Name: PUBLIC LIBRARY ASSOCIATION, a divison of the American Library Association Party/Vendor Contact Person: Tracie D.Hall Contact Phone:312-280-5861 Party/Vendor Address: 225 N.Michigan Ave. City Chicago State: IL Zip: 60601 Department: PLA Amount: Fifteen thousand dollars ($15000.00) Purpose: Digital learning Budget Code(s):10500020-750150 Vendor#N/A Vendor is a BOCC consultant?Yes ❑ No®Contract Type: (Check one)New ®Renewal ❑Amendment ®'fective Date 02/15/2022 Approved by Board Yes ❑No®Agenda Date:N/A---For Section XIV. c. contracts only,Approved by Board in Current FY Budget Yes[—]No This agreement is approved as to technical form and content and I as Department Director affirmatively state work on this project has not been initiated p ' RvceJUaWthon of the agreement: Department Director's Signatur Ems. "`I' Date:2/15/2022 Agreements for emergency services or repair are not subject to the above affirmation. If services related to this agreement have already begun or been completed please briefly describe the nature of the emergency condition that was addressed: N/A Information Technologies (Applicable only to hardware/software purchases or related services)This agreement has been reviewed and is approved as to information technology co ^ cam�e�yifications: JlKA 44ny 2/22/2022 Office of the Chief Information Officer, or Date: Risk Management This agreement is approved for sufficiencQ,tSa cbvvultb awnaw*:standards,specifications,and requirements: Office of the Risk Management Office Date:2/22/2022 Financial Services This instrument has been pre-audited i epfltd pLFquired by the Local Government Budget and Fiscal Control Act: lq'�p '�"�" °'� 2/23/2022 Office of the Chief Financial Office ,awnCJ40Q Date: Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney Date: Clerk to the Board Received for record retention: All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Office of the Clerk to the Board Date: Revised 06/21 012822 9 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 0 Pubiic Library Attachment A -DigitalLearn-Agreement for Services ASSOCIATION 225 N. Michigan Ave, Ste 1300, Chicago, I L 60601 PUBLIC LIBRARY ASSOCIATION 225 N. Michigan Avenue, Suite 1300 Chicago, IL 60601 AGREEMENT FOR SERVICES DigitalLearn.org Library Interface Development THIS AGREEMENT FOR SERVICES ("Agreement") is entered into as of DATE between the American Library Association, an Illinois not-for-profit corporation, acting by and through its Public Library Association Division, 50 E. Huron St., Chicago, IL 60611 (the "Association") and the Orange County Public Library, 137 W. MARGARET LANE HILLSBOROUGH,NC 27278 ("Library"). 1. SERVICES AND SOFTWARE IN GENERAL The Association owns, hosts, updates periodically and manages connectivity to software commonly identified and referenced herein as DigitalLearn.org. DigitalLearn.org is an online resource which builds upon and fosters the work of libraries and community organizations as they work to increase digital literacy across the nation. Included in DigitalLearn.org is a collection of self-directed tutorials for end-users to increase digital literacy, as well as a community of practice for public library-based digital literacy trainers to share resources, tools and best practices. Wherever the term "DigitalLearn.org"is used herein it shall be deemed interchangeable with"DigitalLearn." The Association will provide project management, software, software enhancements, and instructional design services resulting in a customized software interface ("Interface") for access to DigitalLearn.org, which Interface shall be accessible at no cost(except for the fees set forth herein)to the Library. The Association shall provide the Library with the Deliverables described on Exhibit A, attached hereto and made a part hereof by this reference, during the term of the Agreement (the "Deliverables"). 2. COMPENSATION CLAUSES The Library agrees to pay the Association a total of$15,000 for the Deliverables. The Association will invoice the Library upon execution of the Agreement for an amount equal to one half of the total budget($7,500) and will subsequently invoice the Library for the balance ($7,500) when both parties agree customization of the Interface is complete and the Library makes the Interface accessible to learners, or"live."All invoices shall be paid by the Library within thirty(30) days from the date of issue. 3. INDEMNITY Each party hereby agrees to assume responsibility hereunder for the acts of its agents, employees, officers or directors. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 4. STATUS OF THE ASSOCIATION It is understood and agreed that the Association, its employees and its subcontractors are not employees of the Library. Accordingly, the parties recognize and agree that the Library shall have no authority to bind the Association in any contract. Any persons who act on behalf of the Library shall be employees or agents solely of the Library and not of the Association. 5. OWNERSHIP OF WORKPRODUCT, GRANT OF LICENSE AND SOURCE CODE Subject to any rights expressly conferred herein upon Library, Association shall retain any and all right, title and interest, including all copyright, patent, trademark, and trade secret rights, which may arise from the Association's performance pursuant to this Agreement. All Deliverables, including all intellectual property rights contained therein and associated with DigitalLearn.org and provided to the Library as a part of the services under this Agreement shall be owned exclusively by the Association, including but not limited to: (a)work papers, subject code, object code, computer files, proprietary information, processes, methodologies, know how, tools, devices and software; and(b) any modifications, alterations, enhancements, extensions, applications, forms, configurations or derivative works made to the software, excepting only such work papers, subject code, object code, computer files, proprietary information, processes, methodologies, know how, tools, devices and software and/or modifications, alterations, enhancements, extensions, applications, forms configurations or derivative works made to the software solely by Library(collectively referred to herein as "Association Property"). Association Property includes such information as existed prior to the delivery of services and, to the extent such information is of general application, anything which the Association may discover, create or develop during provision of services to the Library. To the extent that the Deliverables contain Association Property, the Association hereby grants to Library a fully-paid-up, non-exclusive, nontransferable,perpetual license to the Association Property as part of the Deliverables for its business purposes. The Association warrants that it has the right to grant the rights to the Association Property including to the Deliverables. The Association Property or Deliverables may not otherwise be disclosed, published or used in whole or in part for any other purpose. Except as otherwise expressly provided herein, neither party shall by reason of this Agreement or its performance obtain any right, title, license or other interest, either express or implied, to the other party's intellectual property. Library hereby agrees not to sell the Association Property, Deliverables or work product created by Association for the benefit of Library pursuant to this Agreement. The Association shall be responsible for software support obligations, in its reasonable discretion, for DigitalLearn.org for so long as the Association has requisite funding to fulfill such support obligations and determines it is in its best interest to do so but in no case shall such support obligations terminate before August 31, 2022. The Library agrees that it shall execute any and all documents necessary to release to the Association any and all rights which the Library may acquire in any property, whether tangible or intangible, in direct connection with the Library's performance pursuant to this Agreement. 6. CONFIDENTIALITY 2 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Unless required by law, the Library and its employees and agents shall not, during the term of this Agreement, or at any time thereafter, disclose any information acquired by the Library pursuant to this Agreement to any third party except as permitted, in writing, by the Association. 7. NONCOMPETITION CLAUSE The Library agrees not to market or sell to members of the Association, any products or services similar to those covered by this Agreement. 8. WARRANTY Association warrants that Association's services will be performed with reasonable care in a diligent and competent manner. Association's sole obligation will be to correct any non- conformance with this warranty, provided that Library gives Association written notice within 30 days after the services are performed or delivered, whichever comes first. The notice will specify and detail the non-conformance and Association will have a reasonable amount of time, based on its severity and complexity, to correct the non-conformance. This warranty is Association's only warranty concerning the services and any Deliverable, and is made expressly in lieu of all other warranties and representations, express or implied, including any implied warranties of merchantability, or fitness for a particular purpose, non-infringement, any implied warranties arising out of association's trade, dealing, or performance or otherwise, all of which are hereby disclaimed. Association will not be liable for any special, consequential, incidental, indirect or exemplary damages or loss (nor any lost profits, savings or business opportunity). Further, Association's liability relating to this Agreement, DigitalLearn.org and any use thereof will in no event exceed an amount equal to the fees (excluding taxes and expenses, if any) Association receives from Library pursuant to this Agreement. Neither party will be liable for any delays or failures in performance due to circumstances beyond its reasonable control. 9. TERMINATION The term of this Agreement shall be from the Effective Date to DATE except in reference to support obligations, which obligations shall terminate on DATE or such later date as is mutually agreed upon. This Agreement may be terminated by either party upon the material breach of this Agreement by the other party or the negligent, fraudulent or criminal act or omission of the other party in the performance of its obligations under this Agreement. Upon termination or expiration for any reason, the Library shall immediately return to the Association all materials issued for its use pursuant to this Agreement. In the event of termination by Library, the Library shall have no further obligation to remit payments to Association,provided nothing herein shall be deemed to be a waiver of such other rights Library may have at law or equity. These obligations will survive the termination of this Agreement and shall remain in full force and effect. 10. NOTICES 3 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 All notices and other communications required or permitted under this Agreement shall be in writing and may be personally delivered, telecopied or sent by first-class mail, postage prepaid, to the parties at their addresses as shown from time to time on the records of the Association. Any party may specify a different address by notifying the Association in writing of such different address. All notices and other communications required or permitted under this Agreement shall be deemed to have been received on the day when personally delivered, telecopied, or three days after being mailed, as the case may be. 11. MISCELLANEOUS A. This Agreement shall be governed by the laws of the State of Illinois, and all questions pertaining to the validity or construction of this Agreement shall be determined in accordance with the internal laws of the State of Illinois without regard to conflict of laws principles. B. There are no oral understandings between the parties to this Agreement. No modification or waiver of any provision of this Agreement shall be valid unless in writing and signed by duly authorized officers of the parties hereto. C. This Agreement may not be assigned by the Library to any other person, firm or corporation without the express written consent of the Association. This Agreement may not be assigned by Association to any other person, firm or corporation without the express written consent of the Library and Association provided however that Association may freely engage subcontractors to perform its obligations under this Agreement. D. The Association and the Library agree to use their best efforts and cooperate in the performance of this Agreement so that its purposes may be successfully carried out, and to engage in good-faith discussions in the event either party is dissatisfied with the performance, conduct or actions of the other. 12. INCORPORATION BY REFERENCE Exhibit A which is attached hereto, is hereby expressly incorporated herein by this reference. IN WITNESS WHEREOF, the parties hereto have caused this Agreement to be executed as of the dates set forth below: ORANGE COUNTY PUBLIC LIBRARY By: Name: Its: Date: 4 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 AMERICAN LIBRARY ASSOCIATION, an Illinois not-for-profit corporation By: Name: Tracie D. Hall Its: Executive Director Date: By: Name: Mary Davis Fournier Its: Executive Director, Public Library Association Date: 5 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 PUBLIC LIBRARY ASSOCIATION DigitalLearn.org Library Interface Development EXHIBIT A-Deliverables The American Library Association,acting by and through its Public Library Association Division ("Association")owns and manages a product entitled DigitalLearn.org. DigitalLearn.org is an online resource which builds upon and fosters the work of libraries and community organizations as they work collaboratively to increase digital literacy across the nation. Included in DigitalLearn.org is a collection of self-directed tutorials for end-users to increase their digital literacy, and a community of practice for digital literacy trainers to share resources,tools and best practices. GOAL The goal is the development of a customized software interface that will support the Library's efforts to assist community members with digital skill attainment. The work products resulting from the performance of this Agreement by Association will include robust tools,features,content and functionality as set forth below. ASSOCIATION SERVICES Association will provide the following services and deliverables to the Library for its use and hereby acknowledges that it shall: (1) Interact with,manage, and pay qualified vendors to accomplish software development, instructional design and other services, as needed,to complete the work described herein. Association will use the services of CKD Technology Partners. or such other vendor as Association chooses for product ownership services,web site support and maintenance,and instructional design services; (2) Facilitate communication between and among Library representatives,Association and vendors in order to develop and refine proposed enhancements to the open source software and interface module,as well as populate specific content(such as registration fields,needs assessment questions,etc.); (3) Oversee development,testing(in collaboration with Library representatives),and launch of the following features and enhancements for Library: (a) Development of capability for learners across Library to: i) login to the site and manage personal accounts; ii) track progress with classes(completions,class progress, etc.)through a learning plan page; iii) access PDFs of certificates for assessments they have completed; iv) access post course content that provides direction and next steps with links and other customizable resources; v) a page that provides direction and next steps for different types of learners with links and other customizable resources vi) take assessments that are task based in order to receive completion certificates; vii) add and remove classes from learners'class progress pages (learning plans); viii) receive class recommendations through a self-directed set of questions; ix) associate with an organization when registering for the site (b) Development of an administrative infrastructure to allow the Library to: 6 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 i) track site and class usage at the aggregate and completion level; and ii) add new class content and make it accessible in the dedicated Library (4) Provide technical support and expertise in order to improve site functionality and usability in addition to keeping technology current. This includes maintaining site and software updates for security,providing incremental support and improvements for increased usability and ongoing support functionality, and rolling out new site functionality and features periodically; and (5) Support hosting and maintenance for the customized software interface following the launch of the site through November 1, 2022 after which date Association and Library must enter into a separate agreement for hosting and maintenance. LIBRARY PARTICIPATION Library will cooperate with Association as reasonably requested to facilitate the delivery of the Services and hereby acknowledges that it shall: (1) Establish an internal development team, including no less than one primary point of contact and ideally 3-4 additional Library staff,to interact with Association and vendors to complete the work described herein; (2) Agree with and adhere to a project timeline developed with the Association and vendors,to initiate and complete development of the customized software interface over a period of 4-6 weeks; (3) Provide all materials(logos, color palettes,user registration field, analytic needs)and services (site review and testing, feedback)required from the Library to create the customized software interface and adhere to the project timeline; (4) Identify and support key staff to serve as administrators of the new customized software interface and ensure those staff have sufficient training to manage the site on an ongoing basis independent of Association and vendors; and (5) Post and maintain on the site a privacy policy, licensing information and attributions of credit for development of the content approved by the Association and make updates to such information upon request by the Association. 7 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Attachment B-DigitalLearn-Cloud Questionnaire 9�gnge = °4�r� Cloud Service Questionnaire This questionnaire is to be used to assess security and legal issues 52 surrounding cloud services under consideration for Orange County. For this questionnaire, cloud services are any services requiring storage of County 11) Cata data outside the County network or provision of computing resources outside of the County network. Vendor under consideration:American Library Association Solution under consideration: DigitalLearn.org Department(s) served: Library 1. Who owns the data created by County personnel using this service? American Library Association nor Jende Solutions retains ownership to any data created by County personnel. Orange county retains ownership of what it creates. 2. Does the Cloud contractually allow the County to access and retrieve its data at the County's discretion? Yes, data including course content and usage statistics is available 24/7 to designated County administrators. If No, Explain: Click here to enter text. 3. Is the Cloud provider contractually obligated to dispose, return or retrieve data in the event of contract termination? Yes: no data is retained on vendor's servers in the event of contract termination.Any course content that County wishes to retain can be retrieved from the platform prior to de-provisioning. If No, Explain: Click here to enter text. 4. Upon such provision of data, is the Cloud provider obligated to specify data format and all information necessary for data extraction? N/A- the only data retained on our servers is County course content and the IP address of end-users who accessed that content while the platform was in use. If No, Explain: Click here to enter text. 5. Is the Cloud provider obligated to destroy all copies of County data, at the County's request? No County data is retained on vendor's servers in the event of contract termination.Any course content that County wishes to retain can be retrieved from the platform prior to de-provisioning. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 If No, Explain: Click here to enter text. 6. What are the Cloud provider's obligation to the County in the event of confirmed or suspected data breaches? N/A: There is no private or confidential County data stored on vendor's servers. In the event of data breach, the only data that can be accessed is data County has already deemed to make public (its generated course content). 7. Is the Cloud provider obligated to inform the County of all locations in which the data is stored(including backups) and to continually keep the County informed of any changes to those locations? N/A: There is no private or confidential County data stored on vendor's servers. If No, Explain: Click here to enter text. 8. What are the Cloud provider's contractual obligations with respect to litigation holds on County data? N/A: There is no private or confidential County data stored on vendor's servers. 9. What are the Cloud provider's contractual prohibitions on disclosing data to individuals, groups or organizations making record requests, unless so directed by an authorized County official? N/A: There is no private or confidential County data stored on vendor's servers. 10. Does the contract obligate the Cloud provider to allow third-party audits and/or certifications related to infrastructure and security, including penetration testing and vulnerability assessment, as requested by the County? Such services are available upon request from County, and at County's expense. Note there is no private or confidential County data stored on vendor's servers. If No, Explain: Click here to enter text. 11. Does the contract obligate the Cloud provider to allow third party onsite inspections of the Cloud provider's infrastructure and security practices on a specified basis? No: There is no private or confidential County data stored on vendor's servers. If No, Explain: Click here to enter text. 12. Does the contract obligate the Cloud provider to provide security documentation upon request by the County? Yes. Note there is no private or confidential County data stored on vendor's servers. If No, Explain: Click here to enter text. 13. Does the contract obligate the Cloud provider to supply the County with the provider's DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 performance records, including access to daily and weekly service quality statistics? No, service records are not available at this time. Note there is no private or confidential County data stored on vendor's servers. If No, Explain: Click here to enter text. 14. Explain the contractually obligated service level parameters, minimum levels, specific remedies and penalties for non-compliance for: 1) Uptime See below 2) Performance and response time: See below 3) Error correction time: See below 4) infrastructure and security: See below PRIORITY DESCRIPTION TIMING 1 Loss of service,or serious impairment of service,which cannot Upon receiving the Support Request, contact the be circumvented.Examples of this type of problem are: Client's primary contact to acknowledge the • Critical product feature does not work(identifiable part of problem report within 60 minutes during the support functionality),no workaround exists,or workarounds are hours. unpractical. Verify the problem and notify the Client's primary Client data is corrupted as a result of a Jende provided contact with the plan of action,within 2 hours. product or feature. Provide updates at least once every 4 hours or at a frequency mutually agreed by Client and Jende until the issue is resolved. 2 A problem exists which can be reason ably_eircumvented by Upon receiving the Support Request, contact the Client or does not materially affect normal operations. Client's primary contact to acknowledge the Examples of this type of problem are: problem report within 4 hours. • A non-functioning product feature which is not critical to Verify the problem and notify the Client's primary a User(identifiable part of functionality). contact with the plan of action within 8 hours. • Part of a product feature is affected,a viable workaround Provide updates at least once every 8 hours or at a exists. frequency mutually agreed by the Client and Jende. • Highly visible usability problem that doesn't affect functionality. 3 Any other issue that does not have any effect on normal Upon receiving report of the problem, verify the operations. problem and notify the Client's primary contact with an acknowledgement and plan of action within 48 hours. • Provide updates at least once every 5 business days or at a frequency mutually agreed by the Client and Jende. 15. Does the contractually defined Service Level Agreement define pertinent terms such as downtime, scheduled downtime, etc...? Yes. If No, Explain: Click here to enter text. 16. Does the contract specify minimum disaster recovery and business continuity requirements, including penalties for non-compliance, as discovered through onsite inspections, audits or actual disasters? N/A If No, Explain: Click here to enter text. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 17. Does the contract require the cloud vendor to notify the County of any outsourced functionality and its provider? N/A If No, Explain: Click here to enter text. 1 S. What are the contractually required notification period for the County or the cloud vendor for termination of the cloud services? 30 Days Notice 19. Describe how the County's data will be stored, managed and archived. N/A There is no private or confidential County data stored on vendor's servers. 20. Will the County's data be stored and managed on a storage system with other data? N/A There is no private or confidential County data stored on vendor's servers. If Yes, Explain: Click here to enter text. 21. At what architectural point in the provider's cloud facility will the County's data be physically connected to networking equipment with non-County data? N/A There is no private or confidential County data stored on vendor's servers. 22. What are the cloud provider's information security policies? Jende Solutions operations, systems and the industry are constantly changing. New threats are routinely introduced to our environment through systems and operations changes as well as periodic changes in our staff. To enforce existing security program criteria as well as identify new threats, Jende Solutions must routinely measure the effectiveness and compliance of its information security program. Policy Statement Jende Solutions will monitor, measure, and evaluate the effectiveness, adequacy, and compliance with its information security program and make adjustments to the program as needed to adequately manage data security risks. This is accomplished by actively performing ongoing system security reviews. Reviews will be performed by Information Technology department staff, the Chief Information Security Officer (CISO), Jende Solutions Internal Audit, and Jende Solutions's auditors or regulators. Summary reports of the effectiveness, adequacy, and compliance will be made periodically to the Security/IT Steering Committee, Jende Solutions Executive Leadership Team, and the Board of Directors. The reports will also discuss changes and additions to the company's information security program deemed advisable to properly protect information assets. Applicability This policy will be enforced by company management and the Security/IT Steering Committee. The scope of audits will impact all managers regarding staff training, risk management and effectiveness of security controls. Standards DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 The CISO is responsible for establishing a monitoring and reporting program that contains the following: • Security Monitoring • Internal Testing • External Examination Risk Management Reviews The Security/IT Steering Committee and Board of Directors of Jende Solutions continuously strive to maintain a clear understanding of the types of information security risks to which Jende Solutions is exposed. This is accomplished by: • Delineating clear accountability and lines of authority across Jende Solutions's businesses and information security activities. • Conducting an annual review of threats and hazards to critical operations and adjusting the information security program accordingly. • Maintaining an active oversight role as products, services, and new technologies are instituted and improved. • Providing clear guidance regarding acceptable levels of security over Jende Solutions's information assets. • Ensuring that the established policies, procedures, and controls are communicated to and observed by all employees. • Annually reviewing and approving information systems and security policies to ensure that the policies address security risks, are aligned with Jende Solutions's overall business and technology strategies, and comply with relevant laws, regulations, and rulings. • Performing an annual review and approval of the internal audit program for scope and frequency concerning compliance with information security policies. Security Monitoring The CISO is responsible for coordinating the monitoring program for all information systems activities and reporting any significant violations to company policy to Senior Management and the Security/IT Steering Committee. This includes oversight of the following duties: IT Department Responsibilities • Perform a periodic review of all systems management logs, system/application activity reports, and disk usage to search for possible security incidents. If a possible intrusion is identified, implement procedures as outlined in the Incident Response Policy. • Perform all scheduled maintenance to include software updates and maintain a log of services performed. • Perform an annual audit of all systems, software and peripheral devices to ensure an accurate software and hardware inventory. • Immediately remove any unlicensed software, hardware, or unauthorized modems from the network or any system. • Periodically review and clear error logs. • Review media backup and anti-virus logs daily to ensure that no viruses are detected and that the data was successfully backed up the previous night. • Periodically review user and group security profiles. This includes reviewing user access to systems and data based upon their business responsibilities, granting access rights based upon these job functions, and ensuring security profiles are promptly modified or revoked upon a change in job function or termination. For each audit entry, the following information will be recorded: ■ Date and Time of event ■ User ID and User involved in the event ■ Type of User action DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 • At least once per month, review system access logs and remove any terminated users from the access control lists. Validate termination lists with Human Resources or the user's supervisor before removal. • Ensure vulnerabilities are managed according to the standards of the Network and Systems Operations Policy. • Logging must be enabled at the operating system, application\database and system level. All logs must be sent to their designated central log system. 90 days of logs will be stored in an online storage in SIEM (Security Information and Event Management) system. At least one year of logs will be maintained at all times, either online or offline, easily accessible in the event of an incident for review. • Ensure that internal and external network vulnerability scans are run at least quarterly and after any significant change in the network (e.g., new system component installations, changes in network topology, firewall rule modifications, product upgrades). • Internal and external vulnerability scans with vulnerabilities will be sent to appropriate teams to address. Rescans will be performed once remediation work has been completed. This will continue until a passing results are obtained. • Conduct periodic "spot checks" of system configurations to ensure standard systems configuration guidelines are being followed. • Ensure that penetration tests are conducted according to the standards of the Network and Systems Operations Policy. • Ensure that a wireless analyzer is used periodically to identify all wireless devices in use. • Ensure that all alerts from file integrity monitors and intrusion detection systems are promptly reviewed. • Test security controls, limitations, network connections and restrictions routinely to make sure they can adequately identify or stop any unauthorized access attempts Internal Audit Testing Methodology • The designated Jende Solutions internal auditor will perform an annual audit of Information Technology (IT) systems. The audit will include testing risk management and operational processes and render a report to the Audit Committee of the Board of Directors regarding the information security program and overall information systems activities and related operations. The auditor and the Chief Information Security Officer (CISO) will track all exceptions. The CISO will prepare a response for any deficiencies identified in the audit report. • The auditor is charged with responsibility for an annual in-depth review of all network and information systems activities, related controls, training support, supporting operations and related policies and procedures, internal reporting systems, and Management's follow-up on previously cited exceptions. Audit reports will be issued to the Executive Leadership Team, the Security/IT Steering Committee, and the Jende Solutions Board of Directors. • This will include internal vulnerability assessment and web application scans being performed at least quarterly and after any significant changes in the network or applications respectively. External Vulnerability Assessment and Penetration Testing • The CISO will supervise an independent assessment for the effectiveness of the Jende Solutions information security program at least once per year. At a minimum, the assessment should include evaluating systems security parameters and profiles such as access controls, password strength, network privileges, system configuration, vulnerability management, security safeguard implementation, staff training, startup files, and login violations. The CISO is also responsible for ensuring penetration tests are performed at least annually and after significant infrastructure changes, application upgrades or modification. • The CISO will also coordinate all required external vulnerability scans to ensure compliance with Jende Solutions Policies. The CISO is responsible for ensuring that all vulnerabilities detected in DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 the scans are reported to the CTO. The CTO will be responsible for ensuring that all identified vulnerabilities are remediated to levels acceptable to the Jende Solutions CISO. • The external assessment will be presented to the Security/IT Steering Committee and Board of Directors to assist in their understanding of threats and hazards for sensitive information and systems. Penetration Testing Methodology Penetration testing allows for the validation of information obtained from vulnerability and web application vulnerability scans. The primary focus of penetration testing it to identify legitimate exploits that could grant an unauthorized user access to the Jende Solutions environment. The groundwork for this test is/will be based on the methodology of Penetration Testing Execution Standard (PTES — www.pentest-standard.org) for systems and network and the Web Application Penetration Testing methodology of OWASP (www.owas.00rg). This is at a high level a four phase process. 1. Phase one— Reconnaissance a. Information gathering via vulnerability assessment tools, port scans and OS fingerprinting. 2. Phase two—Target prioritization a. External—Web or application servers, mail, network, DNS b. Internal—OS patching, database configuration, password security 3. Phase three— Exploitation a. Validating that identified threats can be exploited and capturing sufficient evidence as to allow administrators to effectively implement solutions. 4. Phase four- Re-testing a. Once remediation has been completed, each successfully exploited item must be retested to ensure desired results were achieved. 23. What are the cloud provider's incident management and reporting policies? Information collection, processing, storage and sharing are essential for Jende Solutions to deliver services to its customers. However, that information is also valuable to those who would misuse that data to cause damage to Jende Solutions, or defraud its customers. Jende Solutions has deployed administrative, technical and physical controls to protect sensitive company information as well as customer privacy. However, if controls to protect sensitive data are somehow compromised, Jende Solutions must have an Incident Response Plan to mitigate damage, investigate the cause and recover services. The purpose of this policy is to establish guidelines for the development of Jende Solutions's response to unauthorized network intrusions or other significant information security incidents. Policy Statement Incident Response is the final stage in a process that escalates events through an operation review process to determine if an event was observed on a production processing system could have caused a breach of the system or compromise of sensitive data. Jende Solutions will appoint an Incident Response Team (IRT)and maintain a plan to effectively guide response to an incident. Scope All employees must report all suspicious actions, activities and incidents to the IT department using the Incident reporting form. Standards Jende Solutions will prepare and maintain an incident response plan that will enable the Incident Response Team to respond immediately to a system breach or compromise. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 The plan will address specific incident response procedures, business recovery and continuity procedures, data backup processes, roles and responsibilities, and communication and contact strategies (e.g., informing HHS and State/Local authorities). The intent of the Incident Response Plan is to mitigate risk, and the company will respond to incidents according to the following priorities: • Human life and safety. • Sensitive or mission-critical systems and data. • Other systems and data. • Damage to systems and data. • Disruption to access or services. Specifically, this Incident Response Plan (IRP) is designed to: • Reduce potential direct and indirect financial loss from network intrusions. • Mitigate operational impact from cyber incidents. • Comply with regulatory requirements for information security. • Identify and respond to rogue devices (including wireless access devices)on networks. • Meet industry best practices as published by the FBI and National Infrastructure Protection Center(NIPC). Jende Solutions characterizes cyber incidents as any unwanted, or in some instances, unexplained network or system behavior. Jende Solutions segments these incidents into the following categories consistent with definitions published by the National Infrastructure Protection Center(NIPC): • Increased access to information assets • Unauthorized disclosure of information • Corruption of information • Denial of Service • Theft of IT resources The plan will include: • Roles, responsibilities, and communication strategies in the event of a compromise to include designation of an Incident Response Team (IRT). • Coverage and responses for all critical system components. • Establish a formal process to report incidents and track response activities • Guide response in the following phases: • Preparation • Identification • Containment • Eradication • Recovery • Follow-up/ Lessons Learned • Define escalation processes. • Procedures to conduct a post event review to determine the cause and guide control enhancements. • Procedures for notification, at a minimum, of covered entity and if applicable HHS/OCR. • A strategy for business continuity post compromise. • Reference or inclusion of incident response procedures from the covered entity and if applicable HHS/OCR. • An analysis of legal requirements for reporting compromises as required by State Privacy laws Jende Solutions will ensure: • Integrate event escalation procedures to identify incidents that require declaration of an incident. • Notice will be provided to proper authorities if sensitive data is compromised (See Appendix A for contact numbers). DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 • 24/7 incident response and monitoring coverage for any evidence of unauthorized activity, critical IDS alerts, and/or reports of unauthorized critical system or content file changes. • Specific personnel are designated to be available on a 24/7 basis to respond to compromise alerts. • Provide appropriate training to staff with security breach response responsibilities as is industry standard best practices. • Establish a process to modify and evolve the incident response plan according to lessons learned and to incorporate industry developments. At a minimum, Jende Solutions will conduct a test of the Incident Response plan and the ability of the incident response team to execute the plan on an annual basis. A copy of the test plan and test results will be maintained for a period of at least one year. Any gaps in the security plan or staff training will be identified in the plan testing and reported to the Security/IT Steering Committee for plan modification and incorporation of lessons learned. 24. What is the process by which the cloud provider updates policies and informs customers? N/A DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 25. What is the basic architecture of the cloud provider's network security? (overall design, zones, filters, firewalls, VLANs,protocols, standards) AWS Account vpc Prlvete Subnet — Private Su6ne1 Amnon ..+ EKS Custoers Ffetworks M Aws nos ,p m PG BUJ 1930i AWS WAF 8 Amazon EC2 Kubernetes r� Worker Xdes User Devices Amnion ElaBtiCn[nB 101 neela A.— AmO 33 clauewacca 26. What security measures does the cloud provider use in data storage, transit and use? • Secure (encrypted) transmission of data to external entities or within the company, which involves the following aspects. • Jende Solutions will use strong cryptography and encryption techniques (at least 256 bit) such as Transport Layer Security (TLS) TLS 1.1 or higher, Point-to-Point Tunneling Protocol (PPTP), and Internet Protocol Security (IPSEC) to safeguard confidential data during transmission over public networks. • Confidential information must be encrypted for transmission over wireless networks. The transmissions will be encrypted by using Wi-Fi Protected Access (WPA2) technology if WPA2 capable, and/or VPN or SSL at least 256. • Email encryption software licensed by Jende Solutions will be deployed on personal computers/laptops used by employees. Confidential data must not be sent in unencrypted email. • Jende Solutions will implement encryption for data at rest to ensure that confidential data is unreadable anywhere it is stored, (including data on portable media, in logs, and data received from or stored by wireless networks) by using any of: ■ One-way hash ■ Truncation ■ Index tokens and PADs, with the PADs being securely stored ■ Strong cryptography, such as AES 256-bit • Cryptographic strength must not be less than 256-bits, using industry acceptable encryption or hashing algorithms. • Establish clear procedures and responsibilities for key management; including key rotation, key storage, key selection, and key handling. • Ensure the secure storage and exchange of all access control passwords. • Encryption tokens will be used to deploy"administrator" dual factor authentication, where required. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 • All non-console administrative access will be encrypted using technologies such as SSH, VPN, or TLS 1.1 or newer for web-based management and other non-console administrative access. 27. What encryption technologies does the cloud provider use in data management? See answer to question#26 28. How are access rights managed by the cloud provider for their employees, contractors and other persons? Jende Solutions recognizes that our personnel are the greatest resource in maintaining an effective level of security. At the same time, internal threats can create the greatest risks to information security. No security program can be effective without maintaining security awareness for employees, relevant contractors, and relevant third party users. Relevant contractors and relevant third party users are defined as those personnel with administrative access and/or access to sensitive data/information based on job function, or by accessing Jende Solutions information systems without employee oversight. Every Jende Solutions employee, contractor, third party user, service provider, or vendor is responsible for systems security to the degree that the function requires the use of information and associated systems. Fulfillment of security responsibilities is mandatory and violations of security requirements may be cause for disciplinary action, up to and including dismissal, civil penalties, and criminal penalties. All positions interacting with Jende Solutions information resources must be required to undergo formal processes for access granting, change, and termination. Those positions working with especially sensitive information or powerful privilege must be analyzed to determine any potential vulnerability associated with work in those positions, prior to assignment of these roles. Applicability Jende Solutions Human Resources Department (HR) in conjunction with Management will establish staff guidelines and all staff, relevant contractors and relevant third party users will comply with those guidelines. Standards The Human Resource Department will support the Chief Information Security Officer(CISO)to implement the following personnel security safeguards: • Hiring Practices • Security awareness education and training • Termination Practices Hiring Practices Each new hire granted access to client information and other classified Jende Solutions data will undergo a background check. Any past activity that would subject sensitive systems and data to risk due to an employee's past behavior will be cause to terminate the employment relationship with Jende Solutions. Prior to granting access to classified systems and data, all new hires will receive orientation and training that include responsibilities for protecting classified information. As outlined in the Access Control Policy, a new employees' supervisor must approve access to systems on a "business need-to-know" basis and submit the Systems Access Request Form to both IT and HR for processing. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 The new employee must sign a Statement of Understanding and the Systems Access Request Form acknowledging acceptance of responsibilities contained in the Jende Solutions security policies. These policies will be provided to the employee candidate during orientation. The IT Department will enable access to only those systems approved on the Access Request Form and will retain a copy of the completed form for auditing. Access may only be granted once a signed Statement of Understanding has been received by Human Resources. All new hires must execute a Confidentiality Agreement to protect Jende Solutions sensitive and confidential information, including any client sensitive information. Relevant contractors, relevant third party users, and temporary employees will be held to the same standard as full time employees. A written guarantee from the contractor's organization or the employment agency that a background check has been conducted with respect to relevant contractors and relevant third party users can be used to augment internal background checks. Any vendor that requires access to confidential data regulated by the HIPAA must contractually acknowledge their responsibilities in maintaining regulatory compliance requirements. This requirement is fully described in the Jende Solutions Vendor Management Policy. Training Department managers, at the direction of Human Resources, are responsible for providing security orientation and ongoing instruction to new and existing end-users regarding their department's utilization of Jende Solutions information systems. IT is responsible for informing end-users of pending operational changes affecting technology and to assist them once the changes are in place. New Hire Orientation Each new-hire will complete orientation training to include an overview of Jende Solutions security policies and procedures. The security policies will include end user acceptable use as well as data handling and disposal training in addition to other security safeguards. Moreover, these employees will receive network training as well as training for the use of the systems and applications required to perform their job functions. In-House Instruction All staff, relevant contractors and third party users will be trained on security, compliance, and operating procedures to effectively use Jende Solutions information systems and applications required while performing their duties. In addition, all staff will be given periodic security awareness training including but not limited to a review of relevant Jende Solutions policies and procedures, technology changes, business controls, legal requirements, appropriate use of information processing facilities, reporting information security incidents, the importance of protecting customer customer PII, PHI and other sensitive data types and their handling), and information regarding the disciplinary process for non-compliance with security policies and procedures. This training is performed as new systems or enhancements are introduced or may be annually performed in order to ensure that the staff is following the established policies, procedures and guidelines. The Chief Information Security Officer will periodically perform security and compliance presentations with Senior Management to ensure that they have an understanding of the IT processes and related security control concepts and regulatory requirements. Security Reminders The Chief Information Security Officer will continue security education using sign-in banners, posters, memos, promotions, letters or emails and periodic meetings to re-enforce security training concepts. The DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Information Technology Steering Committee, in conjunction with the Chief Information Security Officer, will assess the adequacy of the security awareness education and training program on a yearly basis. Termination Processes The following standards will be followed upon the resignation of an employee, member of Management, IT Staff contractor or third party user, or service provider. Employee Resignation • Human Resources will immediately notify IT when the resignation is received. • The Supervisor and/or Management Team will determine if access privileges will be continued for the notice period, adjusted or immediately terminated. IT will implement procedures as directed by the Supervisor. • A monthly report will be forwarded to the Chief Information Security Officer by Human Resources that lists all terminations during the month and confirmation that all building access and system access privileges have been terminated. Employee Termination • Human Resources will notify IT immediately upon termination of an employee. • IT will implement procedures as directed by the supervisor to immediately terminate all facility and system access rights. Management Resignation • Human Resources will immediately notify the Chief Information Security Officer when management resignation is received. • Administrative rights to the network will be immediately revoked. User rights will be maintained. • Any server passwords known by the management employee will be immediately changed. • Continued offsite access, as well as the usage of any portable equipment assigned (hardware, software and other materials), will be determined as agreed upon by the remaining executive management team. IT Staff Resignation or Termination • A determination must be made by management as to whether to allow the employee to work during the notice period or to have them leave immediately. • Each of the above procedures for management resignation must be followed. Third Parties (to include temporary workers and contractors) • All hardware, e.g. laptops, security fobs, network hot-spots, will be returned to Jende Solutions on the last day of the person's employment. • All network access will be revoked on the representative's last working day. • All residual vendor or partner management and reporting will be accomplished through the use of hard copy materials or through supervised access to limited information. • All customer information or other confidential Jende Solutions information will be returned to Jende Solutions upon termination of contract. 29. What methods does the cloud provider use to destroy information, when so authorized? Database record removal, log record removal, backup removal of the preceding list. 30. What is the cloud provider's patch management policy/methods? Patching occurs monthly, or earlier depending on security alerts and critical DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 vulnerabilities /threats 31. How does the cloud provider defend against malware, including but not limited to viruses, bots, spyware, spam, phishing and pharming? Jende Solutions will deploy network perimeter controls to regulate traffic moving between trusted internal resources and external, untrusted entities. Jende Solutions's virtual network security controls implementation must protect against known and unknown threats through a combination of a thorough understanding of information risks, best-practice security configurations, and an alignment with Jende Solutions's business requirements. Applicability This policy applies to all the IT staff responsible for managing, implementing, and administering the security of the Jende Solutions networks. Standards Virtual Network administrators will maintain a configuration management program for network devices that identify all key aspects of the program and its management. At a minimum, the program must encompass network controls and routers, and include exact documentation of: • The current network topography (in diagram form, representing logical and physical composition) that includes all connections to and from confidential networks. • A list of all ports and services used for business connections to and from segments carrying confidential data. • Business justification for all insecure ports in use between confidential networks and public/untrusted networks (e.g., FTP, Telnet, etc). • Roles and responsibilities for device management. • The formal process for requesting and implementing changes to network control configuration. The Chief Information Security Officer will conduct periodic reviews of the network control configuration changes to ensure compliance to documented standards and completeness of documentation. Exact standards to be deployed on network devices must adhere to the following: Perimeter Security - Jende Solutions will deploy and maintain perimeter security protection that include: Network Segmentation • All Internet facing applications will be deployed in a Demilitarized Zone (DMZ). All VPN and other secure connections to partners and clients will be routed through the Jende Solutions network controls to establish monitoring and logging controls. Outbound DNS queries from a central DNS service are not required to originate within the DMZ. • All user LAN segments will be separated from production servers through the use of a firewall or an Access Control List (ACL)on the local switch/router. • All servers storing, processing, or transmitting confidential data must be segmented away from both non-confidential servers and user segments by the use of internal routers or firewalls. Virtual Network Controls • Jende Solutions will only use network controls capable of conducting stateful packet inspection. All network controls used to technically support the network control configuration program must have this feature as part of its core technical specification. • Active network controls configurations must comply with the network control configuration program approved by the CISO and maintained in the IT Procedures Guide. Tools will be DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 deployed to alert security personnel if the "running" configuration of any device does not align to the approved "stored" configuration. • All external network connections rules must be approved by the Chief Information Security Officer, and submitted to the Security/IT Steering Committee for review. Changes to the network control ruleset may not be implemented until written approval from the Chief Information Security Officer is obtained. • Network administrators are responsible for maintaining a set of logical and physical network diagrams that fully document all connections to PHI and PII data, including any wireless networks. • Network controls must be installed at each Internet connection and between any DMZ and the Intranet. • The network controls must restrict connections between publicly accessible servers and any system component storing sensitive(I.e. PHI, PII) data, including any connections from wireless networks. As part of the firewall configuration program, all connections between the DMZ and internal networks must be fully documented. • The DMZ must be considered a semi-public network. As such, all connections carrying confidential data within the DMZ (including those originating from trusted, internal networks) must be encrypted. • The network controls must restrict inbound Internet traffic to IP addresses within the DMZ. No direct connections between the Internet and the internal virtual network is allowed. • The network controls must be configured so that RFC 1918 cannot pass from the Internet into the DMZ\externally. Additionally, dynamic packet filtering will be performed to ensure that only established connections are allowed into the network. • Databases with sensitive information will be placed in an internal network zone, segregated from the DMZ.All inbound and outbound Internet traffic will be monitored. • All Internet traffic passing into the DMZ will be limited to ports included in documented business justification that has been approved by the Chief Information Security Officer. • Jende Solutions considers all wireless networks to be public networks. As such, perimeter network controls must be installed between any wireless networks and the internal network. The configuration of these network controls will be set up to deny or control (if such traffic is necessary for business purposes) any traffic from the wireless environment. • Personal firewall software must be installed on any mobile and/or employee-owned computers with direct connectivity to the Internet (e.g., laptops used by employees), which are used to access the Jende Solutions's network. • The network controls must use network address translation (NAT) to mask internal addresses from the Internet. • Direct connections are not allowed between the Internet and the sensitive data (i.e. PII/PHI) environment. • Disclosure of internal IP addressing and routing information to unauthorized third parties is not permitted. • The network controls must limit inbound and outbound traffic to specifically what is necessary for the sensitive data (i.e. PII/PHI)environment and be reviewed on a semi-annually basis. • Network control rules and router access lists will be reviewed and approved every six (6) months by the CISO. 32. What system hardening strategies are employed by the cloud provider? See answer to question#31 33. How does the cloud provider perform security testing, including logging, correlation, intrusion detection, intrusion prevention, file integrity monitoring, time synchronization, DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 security assessments,penetration testing? See answer to question#31 34. What technologies and methods does the cloud vendor provide for strong authentication? Minimum password length, administratively controlled user access 35. Provide any other comments and explanations: Click here to enter text. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Attachment C-DigitalLearn-Cyber Liability Questionnaire_Digital Learning Cyber Policy 01"S% :F ��`�� Cyber Liability Insurance Questionnaire 01' �b This questionnaire is to be used to assess the level of Cyber Liability it 5� Insurance procured by the vendor under consideration for Orange County. °r16 Ca%'D �4 Vendor under consideration:American Library Association Solution under consideration: DigitalLearn.org Department(s) served: Library 1. Do you currently have Cyber Liability Insurance? Yes a. If yes, what coverage is provided by your insurance policy? COVERAGE SCHEDULE(Currency in USID) Limit Retention Each Claim Limit of Liability: Media, Tech,Data&Network Liability: $3,000,000 Policy Aggregate Lim It of Liability: $3,000,000 Additional Defense Limit: Not Included Media,Tech,Data&Network Liability Tech&Professional Services: $3,000,000 each Claim$5,000 Tech Product: $3,000,000 each Claim$5,000 Media: $3,000,000 each Claim$5,000 Data&Network: $3,000,000 each Claim$5,000 Breach Response Breach Response Costs: $3,000,00D each incident$0 Regulatory Defense&Penalties Regulatory Defense&Penalties: $3,000,000 each Claim$5,000 Payment Card Liabilities&Costs Payment Card Liabilities&Costs: $3,000,000 each Claim$5,000 First Party Data&Network Loss Business Interruption Lass: Resulting from Security Breach: $3,000,00D each incident$5,000 Resulting from System Failure: $3,000,000 each incident$5,000 Dependent Business Loss: Resulting from Dependent Security Breach: $250,000 each incident$5,000 Resulting from Dependent System Failure: $250,000 each incident$5,000 Cyber Extortion Loss: $3,000,000 each incident$1,000 Data Recovery Costs: $3,000,ODD each incident$5,000 eCrime Fraudulent Instruction: $250,000 each loss$5,000 Funds Transfer Fraud: $250,000 each loss$5,000 Telephone Fraud: $250,000 each loss$5,000 Criminal Reward Criminal Reward: $50,000 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 b. Provide a copy of the insurance. See Attached. 2. If your answer to question 1 was No, then are you planning to get Cyber Liability Insurance? a. If Yes, When do you plan to get it: b. If No, Explain why not: 3. Provide any other comments and explanations: DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Beazley MediaTech THIS POLICY'S LIABILITY INSURING AGREEMENTS PROVIDE COVERAGE ON A CLAIMS MADE AND REPORTED BASIS AND APPLY ONLY TO CLAIMS FIRST MADE AGAINST THE INSURED DURING THE POLICY PERIOD OR THE OPTIONAL EXTENSION PERIOD (IF APPLICABLE) AND REPORTED TO THE UNDERWRITERS IN ACCORDANCE WITH THE TERMS OF THIS POLICY. AMOUNTS INCURRED AS CLAIMS EXPENSES UNDER THIS POLICY WILL REDUCE AND MAY EXHAUST THE LIMIT OF LIABILITY AND ARE SUBJECT TO RETENTIONS. These Declarations along with the statements contained in the information and materials provided to the Underwriters in connection with the underwriting and issuance of this Policy, and the Policy with endorsements shall constitute the contract between the Insureds and the Underwriters. GENERAL INFORMATION Insurer/Underwriter: Beazley Insurance Company, Inc. (Admitted) Named Insured: Jende Solutions Inc Named Insured Address: 301 University Boulevard Galveston, TX 77555 Notice of Claim, Loss or Beazley Group Circumstance: Attn: Cyber& Tech Claims Group 45 Rockefeller Plaza, 16th floor New York, NY 10111 cyber&techclaims@beazley.com Administrative Notice: Beazley USA Services, Inc. 30 Batterson Park Road Farmington, CT 06032 Tel: (860) 677-3700 Fax: (860) 679-0247 F00730 1 of 4 022019 ed. Date Issued:25-May-2021 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 POLICY INFORMATION Policy Number: VG00003589AB Policy Form: Beazley MediaTech (F00731 022019 ed.) Policy Period: From: 03-Jul-2021 To: 03-Jul-2022 Both at 12:01 AM Local Time at the Named Insured Address Retroactive Date: 05-Feb-2019 Continuity Date: 03-Jul-2020 Optional Extension Period: 12 Months Optional Extension Premium: 100% of the Annual Policy Premium Waiting Period: 8 Hours Premium: $6,864.00 F00730 2 of 4 022019 ed. Date Issued:25-May-2021 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 COVERAGE SCHEDULE (Currency in USD) Limit Retention Each Claim Limit of Liability: Media, Tech, Data &Network Liability: $3,000,000 Policy Aggregate Limit of Liability: $3,000,000 Additional Defense Limit: Not Included Media, Tech, Data& Network Liability Tech & Professional Services: $3,000,000 each Claim$5,000 Tech Product: $3,000,000 each Claim$5,000 Media: $3,000,000 each Claim$5,000 Data& Network: $3,000,000 each Claim$5,000 Breach Response Breach Response Costs: $3,000,000 each incident$0 Regulatory Defense&Penalties Regulatory Defense& Penalties: $3,000,000 each Claim$5,000 Payment Card Liabilities&Costs Payment Card Liabilities&Costs: $3,000,000 each Claim$5,000 First Party Data&Network Loss Business Interruption Loss: Resulting from Security Breach: $3,000,000 each incident$5,000 Resulting from System Failure: $3,000,000 each incident$5,000 Dependent Business Loss: Resulting from Dependent Security Breach: $250,000 each incident$5,000 Resulting from Dependent System Failure: $250,000 each incident$5,000 Cyber Extortion Loss: $3,000,000 each incident$1,000 Data Recovery Costs: $3,000,000 each incident$5,000 eCrime Fraudulent Instruction: $250,000 each loss$5,000 Funds Transfer Fraud: $250,000 each loss$5,000 Telephone Fraud: $250,000 each loss$5,000 Criminal Reward Criminal Reward: $50,000 F00730 3 of 4 022019 ed. Date Issued:25-May-2021 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 ENDORSEMENTS • 1. A01110TX 052020 ed. Important Notice -Texas 2. A01150TX 032014 ed. Notification of the Availability of Loss Control Information/Services - Texas 3. A01801 TX 092019 ed. Texas Amendatory Endorsement 4. BICMU05090406 Nuclear Exclusion 5. E02804 032011 ed. Sanction Limitation and Exclusion Clause 6. E12254 022019 ed. War and Civil War Exclusion 7. E12287 022019 ed. Asbestos, Pollution and Contamination Exclusion Endorsement 8. E12228 022019 ed. Aggregate/Maintenance Retention 9. E12266 022019 ed. Amend Definition of Fraudulent Instruction 10. E12269 022019 ed. GDPR Cyber Endorsement 11. E12289 022019 ed. Computer Hardware Replacement Cost 12. E12290 022019 ed. Contingent Bodily Injury With Sublimit Endorsement 13. E12293 022019 ed. Invoice Manipulation Coverage 14. E12716 022019 ed. Post Breach Remedial Services Endorsement 15. E12864 042019 ed. Crisis Management Expense Coverage 16. E12972 052019 ed. CryptoJacking Endorsement 17. E13040 062019 ed. Reputation Loss 18. E13373 092019 ed. State Consumer Privacy Statutes Endorsement 19. E13916 052020 ed. Employee Device Endorsement 20. E12300 022019 ed. Voluntary Shutdown Coverage 25-May-2021 Authorized Representative Date Secretary President F00730 4 of 4 022019 ed. Date Issued:25-May-2021 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Beazley MediaTech TABLE OF CONTENTS INSURING AGREEMENTS Subsidiary................................................................. 13 System Failure........................................................... 13 Media,Tech, Data&Network Liability..........................1 Tech Products........................................................... 14 Breach Response..........................................................1 Tech&Professional Services Wrongful Act........... 14 Regulatory Defense&Penalties...................................1 Tech Product Wrongful Act...................................... 14 Payment Card Liabilities&Costs.................................1 Tech Services............................................................ 14 First Party Data&Network Loss..................................2 Telephone Fraud....................................................... 14 eCrime............................................................................2 Third Party Information............................................. 14 Criminal Reward............................................................2 Transfer Account...................................................... 14 Unauthorized Access or Use.................................... 14 DEFINITIONS 2 Unauthorized Disclosure.......................................... 14 Waiting Period........................................................... 15 Additional Insured.........................................................2 Breach Notice Law.........................................................3 EXCLUSIONS Breach Response Costs................................................3 Business Interruption Loss...........................................3 Bodily Injury or Property Damage............................ 15 Claim..............................................................................4 Deceptive Business Practices,Antitrust& Claims Expenses...........................................................4 Consumer Protection................................................ 15 Computer Systems........................................................4 Distribution of Information....................................... 15 Continuity Date..............................................................5 Prior Known Acts&Prior Noticed Claims............... 15 Control Group................................................................5 Racketeering, Benefit Plans,Employment Criminal Reward Funds.................................................5 Liability&Discrimination......................................... 16 Cyber Extortion Loss.....................................................5 Sale or Ownership of Securities&Violation of Damages........................................................................5 Securities Laws......................................................... 16 Data................................................................................6 Criminal,Intentional or Fraudulent Acts................. 16 Data Breach....................................................................6 Patent&Misappropriation of Information............... 16 Data&Network Wrongful Act.......................................6 Governmental Actions.............................................. 17 Data Recovery Costs.....................................................6 Other Insureds&Related Enterprises..................... 17 Dependent Business.....................................................6 Trading Losses&Loss of Money............................ 17 Dependent Business Loss............................................6 Contractual................................................................ 17 Dependent Security Breach..........................................7 Retroactive Date........................................................ 17 Dependent System Failure............................................7 Recall.........................................................................18 Digital Currency.............................................................7 Infrastructure Failure................................................ 18 Extortion Payment.........................................................7 Licensing Bodies&Joint Ventures......................... 18 Extortion Threat.............................................................7 Over-Redemption...................................................... 18 Extra Expense................................................................7 First Party Data&Network Loss ............................. 18 Financial Institution.......................................................7 LIMIT OF LIABILITY AND COVERAGE 19 Forensic Expenses........................................................8 Fraudulent Instruction...................................................8 Funds Transfer Fraud....................................................8 RETENTIONS Income Loss...................................................................9 Individual Contractor.....................................................9 OPTIONAL EXTENSI• PERIOD 19 Insured...........................................................................9 Insured Organization.....................................................10 GENERAL CONDITIONS Loss................................................................................10 Media Activities.............................................................10 Notice of Claim or Loss............................................20 Media Material................................................................10 Beazley Breach Response Services........................20 Media Wrongful Act.......................................................10 Notice of Circumstance............................................21 Merchant Services Agreement......................................11 Defense of Claims.....................................................21 Money.............................................................................11 Settlement of Claims.................................................22 Named Insured...............................................................11 Assistance and Cooperation....................................22 PCI Fines Expenses and Costs.....................................11 Subrogation...............................................................23 Penalties.........................................................................11 Other Insurance........................................................23 Period of Restoration....................................................11 Action Against the Underwriters..............................23 Personally Identifiable Information...............................12 Entire Agreement......................................................23 Policy Period..................................................................12 Mergers or Consolidations.......................................23 PrivacyPolicy................................................................12 Assignment...............................................................24 Privacy Policy Violation................................................12 Cancellation..............................................................24 Professional Services....................................................12 Singular Form of a Word..........................................24 RegulatoryProceeding..................................................13 Headings....................................................................24 Retroactive Date............................................................13 Representation by the Insured.................................24 Securities.......................................................................13 Named Insured As Agent..........................................24 SecurityBreach.............................................................13 F00731 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Beazley MediaTech THIS POLICY'S LIABILITY INSURING AGREEMENTS PROVIDE COVERAGE ON A CLAIMS MADE AND REPORTED BASIS AND APPLY ONLY TO CLAIMS FIRST MADE AGAINST THE INSURED DURING THE POLICY PERIOD OR THE OPTIONAL EXTENSION PERIOD (IF APPLICABLE) AND REPORTED TO THE UNDERWRITERS IN ACCORDANCE WITH THE TERMS OF THIS POLICY. AMOUNTS INCURRED AS CLAIMS EXPENSES UNDER THIS POLICY WILL REDUCE AND MAY EXHAUST THE LIMIT OF LIABILITY AND ARE SUBJECT TO RETENTIONS. Please refer to the Declarations, which show the insuring agreements that the Named Insured purchased. If an insuring agreement has not been purchased, coverage under that insuring agreement of this Policy will not apply. The Underwriters agree with the Named Insured, in consideration of the payment of the premium and reliance upon the statements contained in the information and materials provided to the Underwriters in connection with the underwriting and issuance of this Insurance Policy (hereinafter referred to as the "Policy") and subject to all the provisions, terms and conditions of this Policy: INSURING AGREEMENTS Media, Tech, Data & Network Liability To pay Damages and Claims Expenses, which the Insured is legally obligated to pay because of any Claim first made against any Insured during the Policy Period for a: 1. Tech & Professional Services Wrongful Act; 2. Tech Product Wrongful Act; 3. Media Wrongful Act; or 4. Data & Network Wrongful Act. Breach Response To indemnify the Insured Organization for Breach Response Costs incurred by the Insured Organization because of an actual or reasonably suspected Data Breach or Security Breach that the Insured first discovers during the Policy Period. Regulatory Defense & Penalties To pay Penalties and Claims Expenses, which the Insured is legally obligated to pay because of a Regulatory Proceeding first made against any Insured during the Policy Period for a Data Breach or a Security Breach. Payment Card Liabilities & Costs To indemnify the Insured Organization for PCI Fines, Expenses and Costs which it is legally obligated to pay because of a Claim first made against any Insured during the Policy Period. F00731 022019 ed. Page 1 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 First Party Data & Network Loss To indemnify the Insured Organization for: Business Interruption Loss Business Interruption Loss that the Insured Organization sustains as a result of a Security Breach or System Failure that the Insured first discovers during the Policy Period. Dependent Business Interruption Loss Dependent Business Loss that the Insured Organization sustains as a result of a Dependent Security Breach or a Dependent System Failure that the Insured first discovers during the Policy Period. Cyber Extortion Loss Cyber Extortion Loss that the Insured Organization incurs as a result of an Extortion Threat first made against the Insured Organization during the Policy Period. Data Recovery Costs Data Recovery Costs that the Insured Organization incurs as a direct result of a Security Breach or System Failure that the Insured first discovers during the Policy Period. eCrime To indemnify the Insured Organization for any direct financial loss sustained resulting from: 1. Fraudulent Instruction; 2. Funds Transfer Fraud; or 3. Telephone Fraud; that the Insured first discovers during the Policy Period. Criminal Reward To indemnify the Insured Organization for Criminal Reward Funds. DEFINITIONS Additional Insured means any person or entity that the Insured Organization has agreed in writing to add as an Additional Insured under this Policy prior to the commission of any act for which such person or entity would be provided coverage under this Policy, but only to the extent the Insured Organization would have been liable and coverage would have been afforded under the terms and conditions of this Policy had such Claim been made against the Insured Organization. F00731 022019 ed. Page 2 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Breach Notice Law means any statute or regulation that requires notice to persons whose personal information was accessed or reasonably may have been accessed by an unauthorized person. Breach Notice Law also includes any statute or regulation requiring notice of a Data Breach to be provided to governmental or regulatory authorities. Breach Response Costs means the following fees and costs incurred by the Insured Organization with the Underwriters' prior written consent in response to an actual or reasonably suspected Data Breach or Security Breach: 1. for an attorney to provide necessary legal advice to the Insured Organization to evaluate its obligations pursuant to Breach Notice Laws or a Merchant Services Agreement; 2. for a computer security expert to determine the existence, cause and scope of an actual or reasonably suspected Data Breach, and if such Data Breach is actively in progress on the Insured Organization's Computer Systems, to assist in containing it; 3. for a PCI Forensic Investigator to investigate the existence and extent of an actual or reasonably suspected Data Breach involving payment card data and for a Qualified Security Assessor to certify and assist in attesting to the Insured Organization's PCI compliance, as required by a Merchant Services Agreement; 4. to notify those individuals whose Personally Identifiable Information was potentially impacted by a Data Breach; 5. to provide a call center to respond to inquiries about a Data Breach; 6. to provide a credit monitoring, identity monitoring or other personal fraud or loss prevention solution, to be approved by the Underwriters, to individuals whose Personally Identifiable Information was potentially impacted by a Data Breach; and 7. public relations and crisis management costs directly related to mitigating harm to the Insured Organization which are approved in advance by the Underwriters in their discretion. Breach Response Costs will not include any internal salary or overhead expenses of the Insured Organization. Business Interruption Loss means: 1. Income Loss; 2. Forensic Expenses; and 3. Extra Expense; actually sustained during the Period of Restoration as a result of the actual interruption of the Insured Organization's business operations caused by a Security Breach or System Failure. Coverage for Business Interruption Loss will apply only after the Waiting Period has elapsed. F00731 022019 ed. Page 3 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Business Interruption Loss will not include (i) loss arising out of any liability to any third party; (ii) legal costs or legal expenses; (iii) loss incurred as a result of unfavorable business conditions; (iv) loss of market or any other consequential loss; (v) Dependent Business Loss; or(vi) Data Recovery Costs. Claim means: 1. a written demand received by any Insured for money, services, or any non- monetary or injunctive relief; 2. a written request for mediation or arbitration received by any Insured; 3. a civil proceeding against any Insured commenced by service of a complaint or similar proceeding; 4. a written request to toll or waive any applicable statute of limitations; 5. with respect to coverage provided under the Regulatory Defense & Penalties insuring agreement only, institution of a Regulatory Proceeding against any Insured; and Multiple Claims arising from the same or a series of related, repeated or continuing acts, errors, omissions or events will be considered a single Claim for the purposes of this Policy. All such Claims will be deemed to have been made at the time of the first such Claim. Claims Expenses means: 1. all reasonable and necessary legal costs and expenses resulting from the investigation, defense and appeal of a Claim, if incurred by the Underwriters, or by the Insured with the prior written consent of the Underwriters; and 2. the premium cost for appeal bonds for covered judgments or bonds to release property used to secure a legal obligation; provided the Underwriters will have no obligation to appeal or to obtain bonds. Claims Expenses will not include any salary, overhead, or other charges by the Insured for any time spent in cooperating in the defense and investigation of any Claim, or costs to comply with any regulatory orders, settlements or judgments. Computer Systems means computers, any software residing on such computers and any associated devices or equipment (including computers, hardware, software and input and output devices which are part of an industrial control system, including a supervisory control and data acquisition (SCADA)system): 1. operated by and either owned by or leased to the Insured Organization; or 2. with respect to coverage under Part 4. of the Media, Tech, Data & Network Liability insuring agreement, as well as the Breach Response, Regulatory Defense & Penalties and Payment Card Liabilities & Costs insuring agreements, operated by a third party pursuant to written contract with the Insured Organization and used for the purpose of providing hosted computer application services to the Insured Organization or for processing, maintaining, hosting or storing the Insured Organization's electronic data. F00731 022019 ed. Page 4 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Continuity Date means: 1. the Continuity Date listed in the Declarations; and 2. with respect to any Subsidiaries acquired after the Continuity Date listed in the Declarations, the date the Named Insured acquired such Subsidiary. Control Group means any principal, partner, corporate officer, director, general counsel (or most senior legal counsel) or risk manager of the Insured Organization and any individual in a substantially similar position. Criminal Reward Funds means any amount offered and paid by the Insured Organization with the Underwriters' prior written consent for information that leads to the arrest and conviction of any individual(s) committing or trying to commit any illegal act related to any coverage under this Policy; but will not include any amount based upon information provided by the Insured, the Insured's auditors or any individual hired or retained to investigate the illegal acts. All Criminal Reward Funds offered pursuant to this Policy must expire no later than 6 months following the end of the Policy Period. Cyber Extortion Loss means: 1. any Extortion Payment that has been made by or on behalf of the Insured Organization with the Underwriters' prior written consent to prevent or terminate an Extortion Threat; and 2. reasonable and necessary expenses incurred by the Insured Organization with the Underwriters' prior written consent to prevent or respond to an Extortion Threat. Damages means a monetary judgment, award or settlement, including any award of prejudgment or post-judgment interest. With the prior written consent of the Underwriters, Damages also include the direct net cost of providing any future service credits offered by the Insured Organization in lieu of a monetary payment. Damages will not include: 1. future profits, restitution, disgorgement of unjust enrichment or profits by an Insured, or the costs of complying with orders granting injunctive or equitable relief; 2. return or offset of fees, charges or commissions charged by or owed to an Insured for goods or services already provided or contracted to be provided; 3. taxes or loss of tax benefits; 4. fines, sanctions or penalties against any Insured; 5. punitive or exemplary damages or any damages which are a multiple of compensatory damages, unless insurable by law in any applicable venue that most favors coverage for such punitive, exemplary or multiple damages; 6. discounts, coupons, prizes, awards or other incentives offered to the Insured's customers or clients; F00731 022019 ed. Page 5 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 7. liquidated damages, but only to the extent that such damages exceed the amount for which the Insured would have been liable in the absence of such liquidated damages agreement; 8. fines, costs or other amounts an Insured is responsible to pay under a Merchant Services Agreement; or 9. any amounts for which the Insured is not liable, or for which there is no legal recourse against the Insured. Data means any software or electronic data that exists in Computer Systems and that is subject to regular back-up procedures. Data Breach means the theft, loss, or Unauthorized Disclosure of Personally Identifiable Information or Third Party Information that is in the care, custody or control of the Insured Organization or a third party for whose theft, loss or Unauthorized Disclosure of Personally Identifiable Information or Third Party Information the Insured Organization is liable. Data $ Network Wrongful Act means: 1. a Data Breach; 2. a Security Breach; 3. failure to timely disclose a Data Breach or Security Breach; or 4. a Privacy Policy Violation. Data Recovery Costs means the reasonable and necessary costs incurred by the Insured Organization to regain access to, replace, or restore Data, or if Data cannot reasonably be accessed, replaced, or restored, then the reasonable and necessary costs incurred by the Insured Organization to reach this determination. Data Recovery Costs will not include: (i) the monetary value of profits, royalties, or lost market share related to Data, including but not limited to trade secrets or other proprietary information or any other amount pertaining to the value of Data; (ii) legal costs or legal expenses; (iii) loss arising out of any liability to any third party; or (iv) Cyber Extortion Loss. Dependent Business means any entity that is not a part of the Insured Organization but which provides necessary products or services to the Insured Organization pursuant to a written contract. Dependent Business Loss means: 1. Income Loss; and 2. Extra Expense; actually sustained during the Period of Restoration as a result of an actual interruption of the Insured Organization's business operations caused by a Dependent Security Breach or Dependent System Failure. Coverage for Dependent Business Loss will apply only after the Waiting Period has elapsed. F00731 022019 ed. Page 6 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Dependent Business Loss will not include (i) loss arising out of any liability to any third party; (ii) legal costs or legal expenses; (iii) loss incurred as a result of unfavorable business conditions; (iv) loss of market or any other consequential loss; (v) Business Interruption Loss; or(vi) Data Recovery Costs. Dependent Security Breach means a failure of computer security to prevent a breach of computer systems operated by a Dependent Business. Dependent System Failure means an unintentional and unplanned interruption of computer systems operated by a Dependent Business. Dependent System Failure will not include any interruption of computer systems resulting from (i) a Dependent Security Breach, or (ii) the interruption of computer systems that are not operated by a Dependent Business. Digital Currency means a type of digital currency that: 1. requires cryptographic techniques to regulate the generation of units of currency and verify the transfer thereof; 2. is both stored and transferred electronically; and 3. operates independently of a central bank or other central authority. Extortion Payment means Money, Digital Currency, marketable goods or services demanded to prevent or terminate an Extortion Threat. Extortion Threat means a threat to: 1. alter, destroy, damage, delete or corrupt Data; 2. perpetrate the Unauthorized Access or Use of Computer Systems; 3. prevent access to Computer Systems or Data; 4. steal, misuse or publicly disclose Data, Personally Identifiable Information or Third Party Information; 5. introduce malicious code into Computer Systems or to third party computer systems from Computer Systems; or 6. interrupt or suspend Computer Systems; unless an Extortion Payment is received from or on behalf of the Insured Organization. Extra Expense means reasonable and necessary expenses incurred by the Insured Organization during the Period of Restoration to minimize, reduce or avoid Income Loss, over and above those expenses the Insured Organization would have incurred had no Security Breach, System Failure, Dependent Security Breach or Dependent System Failure occurred. Financial Institution means a bank, credit union, saving and loan association, trust company or other licensed financial service, securities broker-dealer, mutual fund, or liquid assets fund or similar investment company where the Insured Organization maintains a bank account. F00731 022019 ed. Page 7 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Forensic Expenses means reasonable and necessary expenses incurred by the Insured Organization to investigate the source or cause of a Business Interruption Loss. Fraudulent Instruction means the transfer, payment or delivery of Money or Securities by an Insured as a result of fraudulent written, electronic, telegraphic, cable, teletype or telephone instructions provided by a third party, that is intended to mislead an Insured through the misrepresentation of a material fact which is relied upon in good faith by such Insured. Fraudulent Instruction will not include loss arising out of: 1. fraudulent instructions received by the Insured which are not first authenticated via a method other than the original means of request to verify the authenticity or validity of the request; 2. any actual or alleged use of credit, debit, charge, access, convenience, customer identification or other cards; 3. any transfer involving a third party who is not a natural person Insured, but had authorized access to the Insured's authentication mechanism; 4. the processing of, or the failure to process, credit, check, debit, personal identification number debit, electronic benefit transfers or mobile payments for merchant accounts; 5. accounting or arithmetical errors or omissions, or the failure, malfunction, inadequacy or illegitimacy of any product or service; 6. any liability to any third party, or any indirect or consequential loss of any kind; 7. any legal costs or legal expenses; or 8. proving or establishing the existence of Fraudulent Instruction. Funds Transfer Fraud means the loss of Money or Securities contained in a Transfer Account at a Financial Institution resulting from fraudulent written, electronic, telegraphic, cable, teletype or telephone instructions by a third party issued to a Financial Institution directing such institution to transfer, pay or deliver Money or Securities from any account maintained by the Insured Organization at such institution, without the Insured Organization's knowledge or consent. Funds Transfer Fraud will not include any loss arising out of: 1. the type or kind covered by the Insured Organization's financial institution bond or commercial crime policy; 2. any actual or alleged fraudulent, dishonest or criminal act or omission by, or involving, any natural person Insured; 3. any indirect or consequential loss of any kind; 4. punitive, exemplary or multiplied damages of any kind or any fines, penalties or loss of any tax benefit; 5. any liability to any third party, except for direct compensatory damages arising directly from Funds Transfer Fraud; F00731 022019 ed. Page 8 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 6. any legal costs or legal expenses; or proving or establishing the existence of Funds Transfer Fraud; 7. the theft, disappearance, destruction of, unauthorized access to, or unauthorized use of confidential information, including a PIN or security code; 8. any forged, altered or fraudulent negotiable instruments, securities, documents or instructions; or 9. any actual or alleged use of credit, debit, charge, access, convenience or other cards or the information contained on such cards. Income Loss means an amount equal to: 1. net profit or loss before interest and tax that the Insured Organization would have earned or incurred; and 2. continuing normal operating expenses incurred by the Insured Organization (including payroll), but only to the extent that such operating expenses must necessarily continue during the Period of Restoration. Individual Contractor means any natural person who performs labor or service for the Insured Organization pursuant to a written contract or agreement with the Insured Organization. The status of an individual as an Individual Contractor will be determined as of the date of an alleged act, error or omission by any such Individual Contractor. Insured means: 1. the Insured Organization; 2. any director or officer of the Insured Organization, but only with respect to the performance of his or her duties as such on behalf of the Insured Organization; 3. an employee (including a part time, temporary, leased or seasonal employee or volunteer) or Individual Contractor of the Insured Organization, but only for work done while acting within the scope of his or her employment and related to the conduct of the Insured Organization's business; 4. a principal if the Named Insured is a sole proprietorship, or a partner if the Named Insured is a partnership, but only with respect to the performance of his or her duties as such on behalf of the Insured Organization; 5. any person who previously qualified as an Insured under parts 2. through 4., but only with respect to the performance of his or her duties as such on behalf of the Insured Organization; 6. an Additional Insured, but only as respects Claims against such person or entity for acts, errors or omissions of the Insured Organization; 7. the estate, heirs, executors, administrators, assigns and legal representatives of any Insured in the event of such Insured's death, incapacity, insolvency or bankruptcy, but only to the extent that such Insured would otherwise be provided coverage under this Policy; and F00731 022019 ed. Page 9 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 8. the lawful spouse, including any natural person qualifying as a domestic partner of any Insured, but solely by reason of any act, error or omission of an Insured other than such spouse or domestic partner. Insured Organization means the Named Insured and any Subsidiaries. Loss means Breach Response Costs, Business Interruption Loss, Claims Expenses, Criminal Reward Funds, Cyber Extortion Loss, Damages, Data Recovery Costs, Dependent Business Loss, PCI Fines, Expenses and Costs, Penalties, loss covered under the eCrime insuring agreement and any other amounts covered under this Policy. Any Loss arising from the same or a series of related, repeated or continuing acts, errors, omissions, incidents or events will be considered a single Loss for the purposes of this Policy. With respect to the Breach Response and First Party Data & Network Loss insuring agreements, all acts, errors, omissions, incidents or events (or series of related, repeated or continuing acts, errors, omissions, incidents or events) giving rise to Loss in connection with such insuring agreements will be deemed to have been discovered at the time the first such act, error, omission, incident or event is discovered. Media Activities means creating, displaying, broadcasting, disseminating or releasing Media Material by or on behalf of the Insured Organization to the public, including any blog, webcasts, websites, broadcast or cable stations, or social media web pages, created and maintained by or on behalf of the Insured Organization. Media Material means any information, including words, sounds, numbers, images or graphics, but will not include computer software or the actual goods, products or services described, illustrated or displayed in such Media Material. Media Wrongful Act means one or more of the following acts committed on or after the Retroactive Date and before the end of the Policy Period in the course of the Insured Organization's performance of Media Activities, Professional Services or Tech Services: 1. defamation, libel, slander, product disparagement, trade libel, infliction of emotional distress, outrage, outrageous conduct, or other tort related to disparagement or harm to the reputation or character of any person or organization; 2. a violation of the rights of privacy of an individual, including false light, intrusion upon seclusion and public disclosure of private facts; 3. invasion or interference with an individual's right of publicity, including misappropriation of any name, persona, voice or likeness for commercial advantage; 4. false arrest, detention or imprisonment; 5. invasion of or interference with any right to private occupancy, including trespass, wrongful entry or wrongful eviction; 6. plagiarism, piracy or misappropriation of ideas under implied contract; 7. infringement of copyright; F00731 022019 ed. Page 10 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 8. infringement of trade dress, domain name, title or slogan, or the dilution or infringement of trademark or service mark, or improper deep-linking or framing or infringement of domain name including cybersquatting violations; 9. negligence regarding the content of any Media Activities, including harm caused through any reliance or failure to rely upon such content; 10. misappropriation of a trade secret; 11. unfair competition including a violation of Section 43(a) of the Lanham Act, but only if alleged in conjunction with and arising out of any of the acts listed in paragraphs 7. or 8. above. Merchant Services Agreement means any agreement between an Insured and a financial institution, credit/debit card company, credit/debit card processor or independent service operator enabling an Insured to accept credit card, debit card, prepaid card or other payment cards for payments or donations. Money means a medium of exchange in current use authorized or adopted by a domestic or foreign government as a part of its currency. Named Insured means the Named Insured listed in the Declarations. PCI Fines, Expenses and Costs means the monetary amount owed by the Insured Organization under the terms of a Merchant Services Agreement as a direct result of a suspected Data Breach. With the prior consent of the Underwriters, PCI Fines, Expenses and Costs includes reasonable and necessary legal costs and expenses incurred by the Insured Organization to appeal or negotiate an assessment of such monetary amount. PCI Fines, Expenses and Costs will not include any charge backs, interchange fees, discount fees or other fees unrelated to a Data Breach. Penalties means: 1. any monetary civil fine or penalty payable to a governmental entity that was imposed in a Regulatory Proceeding; and 2. amounts which the Insured is legally obligated to deposit in a fund as equitable relief for the payment of consumer claims due to an adverse judgment or settlement of a Regulatory Proceeding (including such amounts required to be paid into a "Consumer Redress Fund"); but will not include: (i) costs to remediate or improve Computer Systems; (ii) costs to establish, implement, maintain, improve or remediate security or privacy practices, procedures, programs or policies; (iii) audit, assessment, compliance or reporting costs; or (iv) costs to protect the confidentiality, integrity and/or security of Personally Identifiable Information or other information. The insurability of Penalties will be in accordance with the law in the applicable venue that most favors coverage for such Penalties. Period of Restoration means the 180-day period of time that begins upon the actual and necessary interruption of the Insured Organization's business operations. F00731 022019 ed. Page 11 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Personally Identifiable Information means: 1. any information concerning an individual that is defined as personal information under any Breach Notice Law; and 2. an individual's drivers license or state identification number, social security number, unpublished telephone number, and credit, debit or other financial account numbers in combination with associated security codes, access codes, passwords or PINs; if such information allows an individual to be uniquely and reliably identified or contacted or allows access to the individual's financial account or medical record information. but will not include information that is lawfully made available to the general public. Policy Period means the period of time between the inception date listed in the Declarations and the effective date of termination, expiration or cancellation of this Policy and specifically excludes any Optional Extension Period or any prior policy period or renewal period. Privacy Policy means the Insured Organization's public declaration of its policy for collection, use, disclosure, sharing, dissemination and correction or supplementation of, and access to Personally Identifiable Information. Privacy Policy Violation means the failure by the Insured to comply with that part of a Privacy Policy that specifically: 1. prohibits or restricts the Insured Organization's disclosure, sharing or selling of Personally Identifiable Information; 2. requires the Insured Organization to provide an individual access to Personally Identifiable Information or to correct incomplete or inaccurate Personally Identifiable Information after a request is made; 3. mandates procedures and requirements to prevent the loss of Personally Identifiable Information; 4. prevents or prohibits improper, intrusive or wrongful collection of Personally Identifiable Information from another person; 5. requires notice to a person of the Insured Organization's collection or use of, or the nature of the collection or use of his or her Personally Identifiable Information; or 6. provides a person with the ability to assent to or withhold assent for(e.g. opt-in or opt-out) the Insured Organization's collection or use of his or her Personally Identifiable Information; provided the Insured Organization has in force, at the time of such failure, a Privacy Policy that addresses those subsections above that are relevant to such Claim. Professional Services means professional services performed for others by or on behalf of the Insured Organization for a fee. Professional Services will not include activities performed by or on behalf of the Insured Organization as an accountant, architect, surveyor, health care provider, lawyer, insurance or real estate agent or broker, or civil or structural engineer. F00731 022019 ed. Page 12 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Regulatory Proceeding means a request for information, civil investigative demand, or civil proceeding brought by or on behalf of any federal, state, local or foreign governmental entity in such entity's regulatory or official capacity. Retroactive Date means the applicable date listed in the Declarations. Securities means negotiable and non-negotiable instruments or contracts representing either Money or tangible property that has intrinsic value. Security Breach means a failure of computer security to prevent: 1. Unauthorized Access or Use of Computer Systems, including Unauthorized Access or Use resulting from the theft of a password from a Computer System or from any Insured; 2. a denial of service attack affecting Computer Systems; 3. with respect to coverage under the Liability insuring agreements, a denial of service attack affecting computer systems that are not owned, operated or controlled by an Insured; or 4. infection of Computer Systems by malicious code or transmission of malicious code from Computer Systems. Subsidiary means any entity: 1. which, on or prior to the inception date of this Policy, the Named Insured owns, directly or indirectly, more than 50% of the outstanding voting securities ("Management Control"); and 2. which the Named Insured acquires Management Control after the inception date of this Policy; provided that: (i) the revenues of such entity do not exceed 15% of the Named Insured's annual revenues; or (ii) if the revenues of such entity exceed 15% of the Named Insured's annual revenues, then coverage under this Policy will be afforded for a period of 60 days, but only for any Claim that arises out of any act, error, omission, incident or event first occurring after the entity becomes so owned. Coverage beyond such 60 day period will only be available if the Named Insured gives the Underwriters written notice of the acquisition, obtains the written consent of Underwriters to extend coverage to the entity beyond such 60 day period and agrees to pay any additional premium required by Underwriters. This Policy provides coverage only for acts, errors, omissions, incidents or events that occur while the Named Insured has Management Control over an entity. System Failure means an unintentional and unplanned interruption of Computer Systems. System Failure will not include any interruption of computer systems resulting from (i) a Security Breach, or(ii)the interruption of any third party computer system. F00731 022019 ed. Page 13 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Tech Products means a computer or telecommunications hardware or software product, or related electronic product, that is created, manufactured or developed by the Insured Organization for others, or distributed, licensed, leased or sold by the Insured Organization to others, for compensation, including software updates, service packs and other maintenance releases provided for such products. Tech & Professional Services Wrongful Act means any negligent act, error, omission, misstatement, misleading statement, misrepresentation or unintentional breach of a contractual obligation by the Insured, or by any person or entity for whom the Insured is legally liable, in rendering or failing to render Professional Services or Tech Services that occurs on or after the Retroactive Date and before the end of the Policy Period, but does not mean a Media Wrongful Act. Tech Product Wrongful Act means: 1. any negligent act, error, omission, misstatement, misleading statement, misrepresentation or unintentional breach of a contractual obligation by the Insured that results in the failure of Tech Products to perform the function or serve the purpose intended; or 2. software copyright infringement by the Insured with respect to Tech Products; that occurs on or after the Retroactive Date and before the end of the Policy Period. Tech Services means computer, cloud computing, and electronic technology services, including: 1. data processing, software as a service (SaaS), platform as a service (PaaS), infrastructure as a service (laaS), network as a service (NaaS); 2. data and application hosting, computer systems analysis, and technology consulting and training; or 3. custom software programming for a specific client of the Insured Organization and, computer and software systems installation and integration; performed by the Insured, or by others acting under the Insured Organization's trade name, for others for a fee. Telephone Fraud means the act of a third party gaining access to and using the Insured Organization's telephone system in an unauthorized manner. Third Party Information means any trade secret, data, design, interpretation, forecast, formula, method, practice, credit or debit card magnetic strip information, process, record, report or other item of information of a third party not insured under this Policy which is not available to the general public. Transfer Account means an account maintained by the Insured Organization at a Financial Institution from which the Insured Organization can initiate the transfer, payment or delivery of Money or Securities. Unauthorized Access or Use means the gaining of access to or use of Computer Systems by an unauthorized person(s)or the use of Computer Systems in an unauthorized manner. Unauthorized Disclosure means the disclosure of (including disclosure resulting from phishing) or access to information in a manner that is not authorized by the Insured Organization and is without knowledge of, consent or acquiescence of any member of the Control Group. F00731 022019 ed. Page 14 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Waiting Period means the period of time that begins upon the actual interruption of the Insured Organization's business operations caused by a Security Breach, System Failure, Dependent Security Breach or Dependent System Failure, and ends after the elapse of the number of hours listed as the Waiting Period in the Declarations. EXCLUSIONS The coverage under this Policy will not apply to any Loss arising out of: Bodily Injury or Property Damage 1. physical injury, sickness, disease or death of any person, including any mental anguish or emotional distress resulting from such physical injury, sickness, disease or death; or 2. physical injury to or destruction of any tangible property, including the loss of use thereof; but electronic data will not be considered tangible property; Deceptive Business Practices, Antitrust&Consumer Protection any actual or alleged false, deceptive or unfair trade practices, antitrust violation, restraint of trade, unfair competition (except as provided under part 3. of the Media, Tech, Data & Network Liability insuring agreement), violation of consumer protection law, false, deceptive or misleading advertising, inaccurate cost estimates or failure of goods or services to conform with any represented quality or performance, or violation of the Sherman Antitrust Act, the Clayton Act, or the Robinson-Patman Act; but this exclusion will not apply to: 1. the Breach Response insuring agreement; or 2. coverage for a Data Breach or Security Breach, provided no member of the Control Group participated or colluded in such Data Breach or Security Breach; Distribution of Information the distribution of unsolicited email, text messages, direct mail, facsimiles or other communications, wire tapping, audio or video recording, or telemarketing, if such distribution, wire tapping, recording or telemarketing is done by or on behalf of the Insured Organization; but this exclusion will not apply to Claims Expenses incurred in defending the Insured against allegations of unlawful audio or video recording; Prior Known Acts & Prior Noticed Claims 1. any act, error, omission, incident or event committed or occurring prior to the inception date of this Policy if any member of the Control Group on or before the Continuity Date knew or could have reasonably foreseen that such act, error or omission, incident or event might be expected to be the basis of a Claim or Loss; 2. any Claim, Loss, incident or circumstance for which notice has been provided under any prior policy of which this Policy is a renewal or replacement; F00731 022019 ed. Page 15 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Racketeering, Benefit Plans, Employment Liability & Discrimination 1. any actual or alleged violation of the Organized Crime Control Act of 1970 (commonly known as Racketeer Influenced and Corrupt Organizations Act or RICO), as amended; 2. any actual or alleged acts, errors or omissions related to any of the Insured Organization's pension, healthcare, welfare, profit sharing, mutual or investment plans, funds or trusts; 3. any employer-employee relations, policies, practices, acts or omissions, or any actual or alleged refusal to employ any person, or misconduct with respect to employees; or 4. any actual or alleged discrimination; but this exclusion will not apply to coverage under the Breach Response insuring agreement or coverage for a Data Breach or Security Breach, provided no member of the Control Group participated or colluded in such Data Breach or Security Breach; Sale or Ownership of Securities &Violation of Securities Laws 1. the ownership, sale or purchase of, or the offer to sell or purchase stock or other securities; or 2. an actual or alleged violation of a securities law or regulation; Criminal, Intentional or Fraudulent Acts any criminal, dishonest, fraudulent, or malicious act or omission, or intentional or knowing violation of the law, if committed by an Insured, or by others if the Insured colluded or participated in any such conduct or activity; but this exclusion will not apply to: 1. Claims Expenses incurred in defending any Claim alleging the foregoing until there is a final non-appealable adjudication establishing such conduct; or 2. with respect to a natural person Insured, if such Insured did not personally commit, participate in or know about any act, error, omission, incident or event giving rise to such Claim or Loss. For purposes of this exclusion, only acts, errors, omissions or knowledge of a member of the Control Group will be imputed to the Insured Organization; Patent& Misappropriation of Information 1. infringement, misuse or abuse of patent or patent rights; 2. misappropriation of trade secret arising out of or related to Tech Products or any other products; 3. with respect to any Data & Network Wrongful Act, misappropriation of any Third Party Information (i) by or on behalf of the Insured Organization, or (ii) by any other person or entity if such misappropriation is done with the knowledge, consent or acquiescence of a member of the Control Group; or F00731 022019 ed. Page 16 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 4. disclosure, misuse or misappropriation of any ideas, trade secrets or confidential information that came into the possession of any person or entity prior to the date he or she became an Insured or Subsidiary of the Insured Organization; Governmental Actions a Claim brought by or on behalf of any state, federal, local or foreign governmental entity, in such entity's regulatory or official capacity; but this exclusion will not apply to the Regulatory Defense & Penalties insuring agreement, or any Claim made against the Insured Organization by a governmental entity solely in its capacity as a customer of the Insured Organization; Other Insureds & Related Enterprises a Claim made by or on behalf of: 1. any Insured; but this exclusion will not apply to a Claim made by an individual that is not a member of the Control Group for a Data & Network Wrongful Act, or a Claim made by an Additional Insured; or 2. any business enterprise in which any Insured has greater than 15% ownership interest or made by any parent company or other entity which owns more than 15% of the Named Insured; Trading Losses & Loss of Money 1. any trading losses, trading liabilities or change in value of accounts; 2. any loss, transfer or theft of monies, securities or tangible property of the Insured or others in the care, custody or control of the Insured Organization; or 3. the monetary value of any transactions or electronic fund transfers by or on behalf of the Insured which is lost, diminished, or damaged during transfer from, into or between accounts; but this exclusion will not apply to coverage under the eCrime insuring agreement; Contractual with respect to coverage under parts 1. and 3. of the Media, Tech, Data & Network Liability insuring agreement: any obligation the Insured has under contract; but this exclusion will not apply to: 1. the obligation to perform Professional Services or Tech Services; 2. a Claim for misappropriation of ideas under implied contract, or 3. to the extent the Insured would have been liable in the absence of such contract; Retroactive Date any related or continuing act, error, omission, misstatement, misleading statement, misrepresentation, unintentional breach of a contractual obligation, incident or event where the first such act, error, omission, misstatement, misleading statement, F00731 022019 ed. Page 17 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 misrepresentation or unintentional breach of a contractual obligation, incident or event was committed or occurred prior to the Retroactive Date; Recall any costs or expenses incurred or to be incurred by the Insured or others for the reprinting, reposting, recall, inspection, repair, replacement, removal or disposal of any Tech Products, Media Material or work product, including when resulting from or incorporating the results of Professional Services or Tech Services; but this exclusion will not apply to the resulting loss of use of such Tech Products, Media Material or work product resulting from or incorporating the results of Professional Services or Tech Services; Infrastructure Failure failure or malfunction of satellites or of power, utility, mechanical or telecommunications (including internet) infrastructure or services that are not under the Insured Organization's direct operational control; Licensing Bodies &Joint Ventures 1. the actual or alleged obligation to make licensing fee or royalty payments; or any Claim brought by or on behalf of any intellectual property licensing bodies or organizations; 2. any Claim made by or on behalf of any independent contractor, joint venturer or venture partner arising out of or resulting from disputes over ownership of rights in Media Material or services provided by such independent contractor, joint venturer or venture partner; Over-Redemption 1. any actual or alleged gambling, contest, lottery, promotional game or other game of chance; or 2. the value of coupons, price discounts, prizes, awards, or any other valuable consideration given in excess of the total contracted or expected amount; First Party Data & Network Loss with respect to the First Party Data & Network Loss insuring agreements: 1. seizure, nationalization, confiscation, or destruction of property or data by order of any governmental or public authority; 2. costs or expenses incurred by the Insured to identify or remediate software program errors or vulnerabilities or update, replace, restore, assemble, reproduce, recollect or enhance data or Computer Systems to a level beyond that which existed prior to a Security Breach, System Failure, Dependent Security Breach, Dependent System Failure or Extortion Threat; 3. fire, flood, earthquake, volcanic eruption, explosion, lightning, wind, hail, tidal wave, landslide, act of God or other physical event. F00731 022019 ed. Page 18 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 LIMIT OF • The Policy Aggregate Limit of Liability listed in the Declarations (the "Policy Aggregate Limit of Liability") is the Underwriters' combined total limit of liability for all Loss payable under this Policy. The limit of liability payable under each insuring agreement will be an amount equal to the Policy Aggregate Limit of Liability unless another amount is listed in the Declarations. Such amount is the aggregate amount payable under this Policy pursuant to such insuring agreement and is part of, and not in addition to, the Policy Aggregate Limit of Liability. All Dependent Business Loss payable under this Policy is part of and not in addition to the Business Interruption Loss limit listed in the Declarations. The Underwriters will not be obligated to pay any Loss, or to defend any Claim, after the Policy Aggregate Limit of Liability has been exhausted, or after deposit of the Policy Aggregate Limit of Liability in a court of competent jurisdiction. RETENTIONS The Retention listed in the Declarations applies separately to each act, error, omission, incident, event or related acts, errors, omissions, incidents or events giving rise to a Claim or Loss. The Retention will be satisfied by monetary payments by the Named Insured of covered Loss under each insuring agreement. If any Loss arising out of an incident or Claim is subject to more than one Retention, the Retention for each applicable insuring agreement will apply to such Loss, provided that the sum of such Retention amounts will not exceed the largest applicable Retention amount. Coverage for Business Interruption Loss and Dependent Business Loss will apply after the Waiting Period has elapsed and the Underwriters will then indemnify the Named Insured for all Business Interruption Loss and Dependent Business Loss sustained during the Period of Restoration in excess of the Retention. Satisfaction of the applicable Retention is a condition precedent to the payment of any Loss under this Policy, and the Underwriters will be liable only for the amounts in excess of such Retention. OPTIONAL EXTENSIONPERIOD Upon non-renewal or cancellation of this Policy for any reason except the non-payment of premium, the Named Insured will have the right to purchase, for additional premium in the amount of the Optional Extension Premium percentage listed in the Declarations of the full Policy Premium listed in the Declarations, an Optional Extension Period for the period of time listed in the Declarations. Coverage provided by such Optional Extension Period will only apply to Claims first made against any Insured during the Optional Extension Period and reported to the Underwriters during the Optional Extension Period, and arising out of any act, error or omission committed on or after the Retroactive Date (if applicable) and before the end of the Policy Period. In order for the Named Insured to invoke the Optional Extension Period option, the payment of the additional premium for the Optional Extension Period must be paid to the Underwriters within 60 days of the termination of this Policy. The purchase of the Optional Extension Period will in no way increase the Policy Aggregate Limit of Liability or any sublimit of liability. At the commencement of the Optional Extension Period the entire premium will be deemed earned, and in the event the Named Insured terminates the F00731 022019 ed. Page 19 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Optional Extension Period for any reason prior to its natural expiration, the Underwriters will not be liable to return any premium paid for the Optional Extension Period. All notices and premium payments with respect to the Optional Extension Period option will be directed to the Underwriters through entity listed for Administrative Notice in the Declarations. GENERAL CONDITIONS Notice of Claim or Loss The Insured must notify the Underwriters of any Claim as soon as practicable, but in no event later than: (i) 60 days after the end of the Policy Period; or (ii) the end of the Optional Extension Period (if applicable). Notice must be provided through the contacts listed for Notice of Claim, Loss or Circumstance in the Declarations. With respect to Breach Response Costs, the Insured must notify the Underwriters of any actual or reasonably suspected Data Breach or Security Breach as soon as practicable after discovery by the Insured, but in no event later than 60 days after the end of the Policy Period. Notice must be provided through the contacts listed for Notice of Claim, Loss or Circumstance in the Declarations. Notice of an actual or reasonably suspected Data Breach or Security Breach in conformance with this paragraph will also constitute notice of a circumstance that could reasonably be the basis for a Claim. With respect to Cyber Extortion Loss, the Named Insured must notify the Underwriters via the email address listed in the Notice of Claim, Loss or Circumstance in the Declarations as soon as practicable after discovery of an Extortion Threat but no later than 60 days after the end of the Policy Period. The Named Insured must obtain the Underwriters' consent prior to incurring Cyber Extortion Loss. With respect to Data Recovery Costs, Business Interruption Loss and Dependent Business Loss the Named Insured must notify the Underwriters through the contacts for Notice of Claim, Loss or Circumstance in the Declarations as soon as practicable after discovery of the circumstance, incident or event giving rise to such loss. The Named Insured will provide the Underwriters a proof of Data Recovery Costs, Business Interruption Loss and Dependent Business Loss, and this Policy will cover the reasonable and necessary costs, not to exceed USD 50,000, that the Named Insured incurs to contract with a third party to prepare such proof. All loss described in this paragraph must be reported, and all proofs of loss must be provided, to the Underwriters no later than 6 months after the end of the Policy Period. The Named Insured must notify the Underwriters of any loss covered under the eCrime insuring agreement as soon as practicable, but in no event later than 60 days after the end of the Policy Period. Notice must be provided through the contacts listed for Notice of Claim, Loss or Circumstance in the Declarations. Any Claim arising out of a Loss that is covered under the Breach Response, First Party Data & Network Loss or eCrime insuring agreements and that is reported to the Underwriters in conformance with the foregoing will be considered to have been made during the Policy Period. Beazley Breach Response Services The Underwriters' dedicated business unit focused exclusively on helping Insureds successfully prepare for and respond to actual or suspected Data Breaches and Security Breaches (the "Beazley Breach Response Services Team") will be available to F00731 022019 ed. Page 20 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 assist the Named Insured in responding to an actual or suspected Data Breach or Security Breach. The Beazley Breach Response Services Team will work in collaboration with the Named Insured to triage and assess the severity of a data breach incident, while assisting the coordination of the range of resources and services the Named Insured may need to meet legal requirements and maintain customer confidence. The Beazley Breach Response Services Team may be reached via email at: bbr.claims@beazley.com or via a toll-free 24-Hour Hotline: (866)567-8570. The Named Insured will have access, via the Beazley Breach Response Services Team, to the Underwriters' network of third party breach response service providers, products and services to respond to an actual or suspected Data Breach or Security Breach. Coverage for the costs of products and services provided by any breach response service provider is subject to the terms and conditions of this Policy. The Named Insured will also have access to educational and loss control information and services made available by the Underwriters from time to time and includes access to beazleyb reach solutions.com, a dedicated portal through which it can access news and information regarding breach response planning, data and network security threats, best practices in protecting data and networks, offers from third party service providers, and related information, tools and services. The Named Insured will also have access to communications addressing timely topics in data security, loss prevention and other areas. Notwithstanding the foregoing, an actual or suspected Data Breach or Security Breach must be reported to the Underwriters in accordance with the Notice of Claim or Loss clause in order for such incident to be eligible for coverage under the Breach Response insuring agreement. Assistance from and access to the Beazley Breach Response Services Team will terminate after the Policy Aggregate Limit of Liability has been exhausted, or after deposit of the Policy Aggregate Limit of Liability in a court of competent jurisdiction. Notice of Circumstance With respect to any circumstance that could reasonably be the basis for a Claim, the Insured may give written notice of such circumstance to the Underwriters through the contacts listed for Notice of Claim, Loss or Circumstance in the Declarations as soon as practicable during the Policy Period. Such notice must include: 1. the specific details of the act, error, omission or event that could reasonably be the basis for a Claim; 2. the injury or damage which may result or has resulted from the circumstance; and 3. the facts by which the Insured first became aware of the act, error, omission or event. Any subsequent Claim made against the Insured arising out of any circumstance reported to Underwriters in conformance with the foregoing will be considered to have been made at the time written notice complying with the above requirements was first given to the Underwriters during the Policy Period. Defense of Claims Except with respect to coverage under the Payment Card Liabilities & Costs insuring agreement, the Underwriters have the right and duty to defend any covered Claim or F00731 022019 ed. Page 21 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Regulatory Proceeding. Defense counsel will be mutually agreed by the Named Insured and the Underwriters but, in the absence of such agreement, the Underwriters' decision will be final. With respect to the Payment Card Liabilities & Costs insuring agreement, coverage will be provided on an indemnity basis and legal counsel will be mutually agreed by the Named Insured and the Underwriters. The Underwriters will pay actual loss of salary and reasonable expenses resulting from the attendance by a corporate officer of the Insured Organization at any mediation meetings, arbitration proceedings, hearings, depositions, or trials relating to the defense of any Claim, subject to a maximum of USD 2,000 per day and USD 100,000 in the aggregate, which amounts will be part of and not in addition to the Policy Aggregate Limit of Liability. Settlement of Claims If the Insured refuses to consent to any settlement recommended by the Underwriters and acceptable to the claimant, the Underwriters' liability for such Claim will not exceed: 1. the amount for which the Claim could have been settled, less the remaining Retention, plus the Claims Expenses incurred up to the time of such refusal; plus 2. sixty percent (60%) of any Claims Expenses incurred after the date such settlement or compromise was recommended to the Insured plus sixty percent (60%) of any Damages, Penalties and PCI Fines, Expenses and Costs above the amount for which the Claim could have been settled; and the Underwriters will have the right to withdraw from the further defense of such Claim. The Insured may settle any Claim where the Damages, Penalties, PCI Fines, Expenses and Costs and Claims Expenses do not exceed 50%of the Retention, provided that the entire Claim is resolved and the Insured obtains a full release on behalf of all Insureds from all claimants. Assistance and Cooperation The Underwriters will have the right to make any investigation they deem necessary, and the Insured will cooperate with the Underwriters in all investigations, including investigations regarding coverage under this Policy and the information and materials provided to the underwriters in connection with the underwriting and issuance of this Policy. The Insured will execute or cause to be executed all papers and render all assistance as is requested by the Underwriters. The Insured agrees not to take any action which in any way increases the Underwriters' exposure under this Policy. Expenses incurred by the Insured in assisting and cooperating with the Underwriters do not constitute Claims Expenses under the Policy. The Insured will not admit liability, make any payment, assume any obligations, incur any expense, enter into any settlement, stipulate to any judgment or award or dispose of any Claim without the written consent of the Underwriters, except as specifically provided in the Settlement of Claims clause above. Compliance with a Breach Notice Law will not be considered an admission of liability. F00731 022019 ed. Page 22 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Subrogation If any payment is made under this Policy and there is available to the Underwriters any of the Insured's rights of recovery against any other party, then the Underwriters will maintain all such rights of recovery. The Insured will do whatever is reasonably necessary to secure such rights and will not do anything after an incident or event giving rise to a Claim or Loss to prejudice such rights. If the Insured has waived its right to subrogate against a third party through written agreement made before an incident or event giving rise to a Claim or Loss has occurred, then the Underwriters waive their rights to subrogation against such third party. Any recoveries will be applied first to subrogation expenses, second to Loss paid by the Underwriters, and lastly to the Retention. Any additional amounts recovered will be paid to the Named Insured. Other Insurance The insurance under this Policy will apply in excess of any other valid and collectible insurance available to any Insured unless such other insurance is written only as specific excess insurance over this Policy. Provided, however, this Policy will become primary and non-contributory insurance as respects any insurance maintained by an Additional Insured if primary insurance is required by a contract in place between the Additional Insured and the Insured Organization, but only with respect to any Claim arising solely from the Media, Tech, Data & Network Liability insuring agreements. Action Against the Underwriters No action will lie against the Underwriters or the Underwriters' representatives unless and until, as a condition precedent thereto, the Insured has fully complied with all provisions, terms and conditions of this Policy and the amount of the Insured's obligation to pay has been finally determined either by judgment or award against the Insured after trial, regulatory proceeding, arbitration or by written agreement of the Insured, the claimant, and the Underwriters. No person or organization will have the right under this Policy to join the Underwriters as a party to an action or other proceeding against the Insured to determine the Insured's liability, nor will the Underwriters be impleaded by the Insured or the Insured's legal representative. The Insured's bankruptcy or insolvency of the Insured's estate will not relieve the Underwriters of their obligations hereunder. Entire Agreement By acceptance of the Policy, all Insureds agree that this Policy embodies all agreements between the Underwriters and the Insured relating to this Policy. Notice to any agent, or knowledge possessed by any agent or by any other person, will not effect a waiver or a change in any part of this Policy or stop the Underwriters from asserting any right under the terms of this Policy; nor will the terms of this Policy be waived or changed, except by endorsement issued to form a part of this Policy signed by the Underwriters. Mergers or Consolidations If during the Policy Period the Named Insured consolidates or merges with or is acquired by another entity, or sells more than 50% of its assets to another entity, then this Policy will continue to remain in effect through the end of the Policy Period, but only with respect to events, acts or incidents that occur prior to such consolidation, merger or acquisition. There will be no coverage provided by this Policy for any other Claim or F00731 022019 ed. Page 23 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Loss unless the Named Insured provides written notice to the Underwriters prior to such consolidation, merger or acquisition, the Named Insured has agreed to any additional premium and terms of coverage required by the Underwriters and the Underwriters have issued an endorsement extending coverage under this Policy. Assignment The interest hereunder of any Insured is not assignable. If the Insured dies or is adjudged incompetent, such insurance will cover the Insured's legal representative as if such representative were the Insured, in accordance with the terms and conditions of this Policy. Cancellation This Policy may be cancelled by the Named Insured by giving written notice to the Underwriters through the entity listed for Administrative Notice in the Declarations stating when the cancellation will be effective. This Policy may be cancelled by the Underwriters by mailing to the Named Insured at the address listed in the Declarations written notice stating when such cancellation will be effective. Such date of cancellation will not be less than 60 days (or 10 days for cancellation due to non-payment of premium) after the date of notice. If this Policy is canceled in accordance with the paragraphs above, the earned premium will be computed pro rata; but the premium will be deemed fully earned if any Claim, or any circumstance that could reasonably be the basis for a Claim or Loss, is reported to the Underwriters on or before the date of cancellation. Payment or tender of unearned premium is not a condition of cancellation. Singular Form of a Word Whenever the singular form of a word is used herein, the same will include the plural when required by context. Headings The titles of paragraphs, clauses, provisions or endorsements of or to this Policy are intended solely for convenience and reference, and are not deemed in any way to limit or expand the provisions to which they relate and are not part of the Policy. Representation by the Insured All Insureds agree that the statements contained the information and materials provided to the Underwriters in connection with the underwriting and issuance of this Policy are true, accurate and are not misleading, and that the Underwriters issued this Policy, and assume the risks hereunder, in reliance upon the truth thereof. Named Insured as Agent The Named Insured will be considered the agent of all Insureds, and will act on behalf of all Insureds with respect to the giving of or receipt of all notices pertaining to this Policy, and the acceptance of any endorsements to this Policy. The Named Insured is responsible for the payment of all premiums and Retentions and for receiving any return premiums. F00731 022019 ed. Page 24 of 24 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Have a complaint or need help? If you have a problem with a claim or your premium, call your insurance company or HMO first. If you can't work out the issue, the Texas Department of Insurance may be able to help. Even if you file a complaint with the Texas Department of Insurance, you should also file a complaint or appeal through your insurance company or HMO. If you don't, you may lose your right to appeal. Beazley USA Services, Inc. (on behalf of one or more Beazley Group insurers) To get information or file a complaint with your insurance company or HMO: Call: Compliance Department at 1-860-677-3700 Toll Free: 1-866-623-2953 Online: www.beazley.com Email: us.complaints(a)beazley.com Mail: 30 Batterson Park Road Farmington, CT 06032 The Texas Department of Insurance To get help with an insurance question or file a complaint with the state: Call with a question: 1-800-252-3439 File a complaint: www.tdi.texas.gov Email: ConsumerProtection(a�tdi.texas.gov Mail: MC 111-1A P.O. Box 149091 Austin, TX 78714-9091 A01110TX Page 1 of 2 052020 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 jiene una queja o necesita ayuda? Si tiene un problema con una reclamacion o con su prima de seguro, Ilame primero a su compania de seguros o HMO. Si no puede resolver el problema, es posible que el Departamento de Seguros de Texas (Texas Department of Insurance, por su nombre en ingles) pueda ayudar. Aun si usted presenta una queja ante el Departamento de Seguros de Texas, tambien debe presentar una queja a traves del proceso de quejas o de apelaciones de su compania de seguros o HMO. Si no to hace, podria perder su derecho para apelar. Beazley USA Services, Inc. (on behalf of one or more Beazley Group insurers) Para obtener informacion o para presenter una queja ante su compania de seguros o HMO: Llame a: Compliance Departmental 1-860-677-3700 Telefono gratuito: 1-866-623-2953 En linea: www.beazleV.com Correo electronico: us.complaints(d-)beazley.com Direccion postal: 30 Batterson Park Road Farmington, CT 06032 El Departamento de Seguros de Texas Para obtener ayuda con una pregunta relacionada con los seguros o para presentar una queja ante el estado: Llame con sus preguntas al: 1-800-252-3439 Presente una queja en: www.tdi.texas.gov Correo electronico: ConsumerProtection(a tdi.texas.gov Direccion postal: MC 111-1A P.O. Box 149091 Austin, TX 78714-9091 A01110TX Page 2 of 2 052020 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 NOTIFICATION OF THE AVAILABILITY OF LOSS CONTROL INFORMATION/SERVICES -TEXAS Beazley Insurance Company, Inc. is committed to providing loss control information and services to its Texas policyholders at no charge in an effort to prevent and reduce potential claims. To obtain information or to request services, you may call: Jennifer Englund Compliance 1-866-623-2953 You may also request this information by writing to: Beazley Insurance Company, Inc. 30 Batterson Park Road Farmington, Connecticut 06032 Attn: Jennifer Englund Compliance A01150TX Page 1 of 1 032014 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" TEXAS AMENDATORY ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech 1. The NOTICE at the top of the first page above the INSURING AGREEMENTS section is amended to add ", Automatic Extension Period" before the words"or Optional Extension Period (if applicable)". 2. The following is added to the Settlement of Claims provision of the GENERAL CONDITIONS section: The Underwriters shall provide written notice to the Named Insured of an initial offer to settle or compromise a Claim against an Insured, not less than ten (10) days after the date on which the offer to settle or compromise is made, unless the Named Insured advised the Underwriters of such initial offer to settle or compromise the Claim. The Underwriters shall also provide written notice to the Named Insured of the settlement of a Claim against an Insured, not less than thirty (30) days after the settlement. 3. The phrase "Optional Extension Period", wherever it appears, shall be deemed to include "Automatic Extension Period". 4. The OPTIONAL EXTENSION PERIOD section is deleted in its entirety and replaced with the following: AUTOMATIC AND OPTIONAL EXTENSION PERIODS The Named Insured shall have an automatic thirty (30) day extension of the coverage granted by this Policy following the effective date of cancellation or nonrenewal, but only with respect to any act, error or omission committed on or after the Retroactive Date and before the effective date of cancellation or nonrenewal. This period shall be referred to herein as the "Automatic Extension Period". If the Underwriters or the Named Insured cancels or nonrenews this Policy for any reason except the non-payment of premium, then the Named Insured shall have the right, upon payment of an additional premium calculated at that percentage shown in the Optional Extension Premium provision of the Declarations of the total premium for this Policy, to an extension of the coverage granted by this Policy with respect to any Claim first made against any Insured and reported in writing to the Underwriters during the period of time set forth in the Optional Extension Period provision of the Declarations after the end of the Automatic Extension Period, but only with respect to any act, error or omission committed on or after the Retroactive Date and before the effective date of cancellation or nonrenewal. The Optional Extension Period offered by the Underwriters shall be at least one year in length. The right to purchase the Optional Extension Period shall terminate unless written notice together with full payment of the premium for the Optional Extension Period is given to the Underwriters within thirty (30) days after the effective date of cancellation or nonrenewal. If such notice and premium payment is not so given to the Underwriters, there shall be no right to purchase the Optional Extension Period. In the event of the purchase of the Optional Extension Period, the entire premium for the Optional Extension Period shall be deemed earned at its commencement. A01801 TX Page 1 of 3 092019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 The Automatic Extension Period and the purchase of the Optional Extension Period shall not in any way increase the Limit of Liability of the Underwriters. 5. The title of the Cancellation provision in the GENERAL CONDITIONS section is changed to Cancel lation/Nonrenewal. 6. The second paragraph of the Cancellation/Nonrenewal provision in the GENERAL CONDITIONS section is deleted in its entirety and replaced by the following: If this Policy has been in effect for sixty(60) days or less and is not a renewal Policy, the Underwriters may cancel this Policy for any reason. If this Policy has been in effect for more than sixty (60) days, the Underwriters may only cancel this Policy for any of the following reasons: 1. fraud in obtaining coverage; 2. failure to pay premiums when due; 3. increase in hazard within the control of the Insured that would produce a rate increase; 4. loss of the Underwriters' reinsurance covering all or part of the risk covered by the Policy; or 5. the Underwriters are placed in supervision, conservatorship, or receivership and the cancellation is approved or directed by the supervisor, conservator, or receiver. The Underwriters may cancel this Policy by mailing or delivering to the Named Insured written notice stating when, not less than ten (10) days thereafter, such cancellation shall be effective. The notice of cancellation shall state the reason for cancellation. The mailing of such notice shall be sufficient notice and the effective date of cancellation stated in the notice shall become the end of the Policy Period. Delivery of such written notice by the Underwriters shall be equivalent to mailing. The Underwriters shall not cancel this Policy based solely on the fact that the Insured is an elected official. 7. The phrase "; but the premium will be deemed fully earned if any Claim, or any circumstance that could reasonably be the basis for a Claim or Loss, is reported to the Underwriters on or before the date of cancellation" in the third paragraph of the Cancel lation/Nonrenewal provision in the GENERAL CONDITIONS section is deleted. 8. The following is added to the Cancellation/Nonrenewal provision in the GENERAL CONDITIONS section: If the Underwriters decide not to renew this Policy, the Underwriters shall mail or deliver written notice to the Named Insured at the address shown in the Declarations at least sixty (60) days before the end of the Policy Period. The notice of nonrenewal shall state the reason for nonrenewal. If notice of nonrenewal is delivered or mailed later than the 60th day before the date the Policy expires, the Policy's coverage shall remain in effect until the 61st day after the date on which the notice is delivered or mailed. Earned premium for any period of coverage that extends beyond the Policy's expiration date shall be computed pro rata based on the Policy's current rate. If this Policy is so extended, such period of extended coverage shall be part of and not in addition to the Policy Period. The Underwriters shall not refuse to renew this Policy based solely on the fact that the Insured is an elected official. The regulatory requirements set forth in this Amendatory Endorsement shall supersede and take precedence over any provisions of this Policy or any endorsement to this Policy, whenever added, that A01801 TX Page 2 of 3 092019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 are inconsistent with or contrary to the provisions of this Amendatory Endorsement, unless such Policy or endorsement provisions comply with the applicable insurance laws of this state. All other terms and conditions of this Policy remain unchanged. Authorized Representative A01801 TX Page 3 of 3 092019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" NUCLEAR EXCLUSION This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that this Policy does not apply: I. Under any Liability Coverage, to injury, sickness, disease, death or destruction: (a) with respect to which an insured under the Policy is also an insured under a nuclear energy liability policy issued by Nuclear Energy Liability Insurance Association, Mutual Atomic Energy Liability Underwriters or Nuclear Insurance Association of Canada, or would be an insured under any such policy but for its termination upon exhaustion of its limit of liability; or (b) resulting from the hazardous properties of nuclear material and with respect to which (1)any person or organization is required to maintain financial protection pursuant to the Atomic Energy Act of 1954, or any law amendatory thereof, or(2)the insured is, or had this Policy not been issued would be, entitled to indemnity from the United States of America, or any agency thereof, under any agreement entered into by the United States of America, or any agency thereof, with any person or organization. II. Under any Medical Payments Coverage, or under any Supplementary Payments Provision relating to immediate medical or surgical relief, to expenses incurred with respect to bodily injury, sickness, disease or death resulting from the hazardous properties of nuclear material and arising out of the operation of a nuclear facility by any person or organization. III. Under any Liability Coverage, to injury, sickness, disease, death or destruction resulting from the hazardous properties of nuclear material, if: (a) the nuclear material (1) is at any nuclear facility owned by, or operated by or on behalf of, an insured or(2) has been discharged or dispersed therefrom; (b) the nuclear material is contained in spent fuel or waste at any time possessed, handled, used, processed, stored, transported or disposed of by or on behalf of an insured; or (c) the injury, sickness, disease, death or destruction arises out of the furnishing by an insured of services, materials, parts or equipment in connection with the planning, construction, maintenance, operation or use of any nuclear facility, but if such facility is located within the United States of America, its territories or possessions or Canada, this exclusion (c) applies only to injury to or destruction of property at such nuclear facility. IV. As used in this endorsement: BICMU05090406 Page 1 of 2 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 "hazardous properties" include radioactive, toxic or explosive properties; "nuclear material" means source material, special nuclear material or by-product material; "source material", "special nuclear material", and "by-product material" have the meanings given them in the Atomic Energy Act 1954 or in any law amendatory thereof; "spent fuel" means any fuel element or fuel component, solid or liquid, which has been used or exposed to radiation in a nuclear reactor; "waste" means any waste material (1) containing by-product material and (2) resulting from the operation by any person or organization of any nuclear facility included within the definition of nuclear facility under paragraph (a) or (b) thereof; "nuclear facility" means: (a) any nuclear reactor, (b) any equipment or device designed or used for(1) separating the isotopes of uranium or plutonium, (2) processing or utilizing spent fuel, or(3) handling, processing or packaging waste, (c) any equipment or device used for the processing, fabricating or alloying of special nuclear material if at any time the total amount of such material in the custody of the insured at the premises where such equipment or device is located consists of or contains more than 25 grams of plutonium or uranium 233 or any combination thereof, or more than 250 grams of uranium 235, (d) any structure, basin, excavation, premises or place prepared or used for the storage or disposal of waste, and includes the site on which any of the foregoing is located, all operations conducted on such site and all premises used for such operations; "nuclear reactor" means any apparatus designed or used to sustain nuclear fission in a self-supporting chain reaction or to contain a critical mass of fissionable material. With respect to injury to or destruction of property, the word "injury" or "destruction" includes all forms of radioactive contamination of property. All other terms and conditions of this Policy remain unchanged. Authorized Representative BICMU05090406 Page 2 of 2 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" SANCTION LIMITATION AND EXCLUSION CLAUSE This endorsement modifies insurance provided under the following: Beazley MediaTech No (re)insurer shall be deemed to provide cover and no (re)insurer shall be liable to pay any claim or provide any benefit hereunder to the extent that the provision of such cover, payment of such claim or provision of such benefit would expose that (re)insurer to any sanction, prohibition or restriction under United Nations resolutions or the trade or economic sanctions, law or regulations of the European Union, United Kingdom or United States of America. All other terms and conditions of this Policy remain unchanged. Authorized Representative E02804 Page 1 of 1 032011 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" WAR AND CIVIL WAR EXCLUSION This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that EXCLUSIONS is amended to include: War and Civil War or resulting from, directly or indirectly occasioned by, happening through or in consequence of: war, invasion, acts of foreign enemies, hostilities (whether war be declared or not), civil war, rebellion, revolution, insurrection, military or usurped power or confiscation or nationalization or requisition or destruction of or damage to property by or under the order of any government or public or local authority; provided, that this exclusion will not apply to Cyber Terrorism. For purposes of this exclusion, "Cyber Terrorism" means the premeditated use of disruptive activities, or threat to use disruptive activities, against a computer system or network with the intention to cause harm, further social, ideological, religious, political or similar objectives, or to intimidate any person(s) in furtherance of such objectives. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12254 Pagel of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" ASBESTOS, POLLUTION, AND CONTAMINATION EXCLUSION ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that the coverage under this Policy will not apply to any Loss arising out of either in whole or in part, directly or indirectly arising out of or resulting from or in consequence of, or in any way involving: 1. asbestos, or any materials containing asbestos in whatever form or quantity; 2. the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of any fungi, molds, spores or mycotoxins of any kind; any action taken by any party in response to the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of fungi, molds, spores or mycotoxins of any kind, such action to include investigating, testing for, detection of, monitoring of, treating, remediating or removing such fungi, molds, spores or mycotoxins; and any governmental or regulatory order, requirement, directive, mandate or decree that any party take action in response to the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of fungi, molds, spores or mycotoxins of any kind, such action to include investigating, testing for, detection of, monitoring of, treating, remediating or removing such fungi, molds, spores or mycotoxins; The Underwriters will have no duty or obligation to defend any Insured with respect to any Claim or governmental or regulatory order, requirement, directive, mandate or decree which either in whole or in part, directly or indirectly, arises out of or results from or in consequence of, or in any way involves the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of any fungi, molds, spores or mycotoxins of any kind; 3. the existence, emission or discharge of any electromagnetic field, electromagnetic radiation or electromagnetism that actually or allegedly affects the health, safety or condition of any person or the environment, or that affects the value, marketability, condition or use of any property; or 4. the actual, alleged or threatened discharge, dispersal, release or escape of Pollutants; or any governmental,judicial or regulatory directive or request that the Insured or anyone acting under the direction or control of the Insured test for, monitor, clean up, remove, contain, treat, detoxify or neutralize Pollutants. Pollutants means any solid, liquid, gaseous or thermal irritant or contaminant including gas, acids, alkalis, chemicals, heat, smoke, vapor, soot, fumes or waste. Waste includes but is not limited to materials to be recycled, reconditioned or reclaimed. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12287 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" AGGREGATE/MAINTENANCE RETENTION This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The maximum aggregate Retention for all Claims made during any Policy Year under this Policy shall be $15,000 provided, that the each Claim Retention set forth in item 3. below shall not be subject to any aggregate Retention. 2. For purposes of this endorsement, the term "Policy Year" means each 365 day period beginning with the Inception Date of the Policy Period and each such succeeding Policy Period, if any. 3. With respect to any Claim made in any Policy Year after the maximum aggregate Retention is reached for that Policy Year, the each Claim Retention shall be $0. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12228 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" AMEND DEFINITION OF FRAUDULENT INSTRUCTION This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that the definition of Fraudulent Instruction is deleted in its entirety and replaced with the following: Fraudulent Instruction means the transfer, payment or delivery of Money or Securities by an Insured as a result of fraudulent written, electronic, telegraphic, cable, teletype or telephone instructions provided by a third party, that is intended to mislead an Insured through the misrepresentation of a material fact which is relied upon in good faith by such Insured. Fraudulent Instruction will not include loss arising out of: 1. any actual or alleged use of credit, debit, charge, access, convenience, customer identification or other cards; 2. any transfer involving a third party who is not a natural person Insured, but had authorized access to the Insured's authentication mechanism; 3. the processing of, or the failure to process, credit, check, debit, personal identification number debit, electronic benefit transfers or mobile payments for merchant accounts; 4. accounting or arithmetical errors or omissions, or the failure, malfunction, inadequacy or illegitimacy of any product or service; 5. any liability to any third party, or any indirect or consequential loss of any kind; 6. any legal costs or legal expenses; or 7. proving or establishing the existence of Fraudulent Instruction. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12266 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" GDPR CYBER ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that the definition of Data & Network Wrongful Act is amended to include the following: 5. non-compliance with the following obligations under the EU General Data Protection Regulation: (i) Article 5.1(f), also known as the Security Principle; (ii) Article 32, Security of Processing; (iii) Article 33, Communication of a Personal Data Breach to the Supervisory Authority; or (iv) Article 34, Communication of a Personal Data Breach to the Data Subject. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12269 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" COMPUTER HARDWARE REPLACEMENT COST This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The definition of Extra Expense is deleted in its entirety and replaced with the following: Extra Expense means reasonable and necessary expenses incurred by the Insured Organization during the Period of Restoration to minimize, reduce or avoid Income Loss, over and above those expenses the Insured Organization would have incurred had no Security Breach, System Failure, Dependent Security Breach or Dependent System Failure occurred; and includes reasonable and necessary expenses incurred by the Insured Organization to replace computers or any associated devices or equipment operated by, and either owned by or leased to, the Insured Organization that are unable to function as intended due to corruption or destruction of software or firmware directly resulting from a Security Breach, provided however that the maximum sublimit applicable to Extra Expense incurred to replace such devices or equipment is USD $100,000. 2. Part 2. of the Bodily Injury or Property Damage exclusion is deleted in its entirety and replaced with the following: 2. physical injury to or destruction of any tangible property, including the loss of use thereof; but this will not apply to the loss of use of computers or any associated devices or equipment operated by, and either owned by or leased to, the Insured Organization that are unable to function as intended due to corruption or destruction of software or firmware directly resulting from a Security Breach. Electronic data shall not be considered tangible property; All other terms and conditions of this Policy remain unchanged. Authorized Representative E12289 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" CONTINGENT BODILY INJURY WITH SUBLIMIT ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The Bodily Injury or Property Damage exclusion is deleted in its entirety and replaced with the following: Bodily Injury or Property Damage 1. Bodily Injury; provided, this exclusion shall not apply to any Claim for Contingent Bodily Injury; and 2. physical injury to or destruction of any tangible property, including the loss of use thereof; but electronic data will not be considered tangible property; 2. DEFINITIONS is amended by the addition of: Bodily Injury means physical injury, sickness, disease or death of any person, including any mental anguish or emotional distress that results from such physical injury, sickness, disease or death. Contingent Bodily Injury means those Claims wherein the Damages sought by the claimant are for Bodily Injury which arise solely out of a Security Breach affecting the Insured Organization's Computer Systems which is otherwise covered under the terms and conditions of this Policy; but not if the Insured's own act, error or omission is the direct immediate cause of such Claim for Bodily Injury. Furthermore, this extension of coverage applies only if such Claim for Bodily Injury is not covered under any other policy of insurance. 3. The Underwriter's aggregate limit of liability for all Damages resulting from all Claims covered under this Endorsement, made against any Insured(s) based upon, arising out of, directly or indirectly resulting from or in consequence of, or in any way involving any Contingent Bodily Injury shall be $250,000, which amount shall be part of and not in addition to the Policy Aggregate Limit of Liability. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12290 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" INVOICE MANIPULATION COVERAGE This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The aggregate sublimit applicable to all loss under this endorsement is USD $100,000. 2. The Retention applicable to each incident, event, or related incidents or events, giving rise to an obligation to pay loss under this endorsement shall be USD $5,000. 3. INSURING AGREEMENTS is amended to include: Invoice Manipulation To indemnify the Insured Organization for Direct Net Loss resulting directly from the Insured Organization's inability to collect Payment for any goods, products or services after such goods, products or services have been transferred to a third party, as a result of Invoice Manipulation that the Insured first discovers during the Policy Period: 4. DEFINITIONS is amended to include: Direct Net Loss means the direct net cost to the Insured Organization to provide goods, products or services to a third party. Direct Net Loss will not include any profit to the Insured Organization as a result of providing such goods, products or services. Invoice Manipulation means the release or distribution of any fraudulent invoice or fraudulent payment instruction to a third party as a direct result of aSecurity Breach or a Data Breach. Payment means currency, coins or bank notes in current use and having a face value. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12293 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" Post Breach Remedial Services Endorsement This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that, following a covered Data Breach or Security Breach involving the actual Unauthorized Access or Use of the Insured Organization's Computer Systems for which the Insured Organization has utilized services exclusively from Beazley Service Providers, the Insured Organization will be eligible to receive Post Breach Remedial Services. Post Breach Remedial Services means up to 100 hours per Policy Period of post-breach computer security consultation and remedial services to be provided by Lodestone Security ("Lodestone"). Such services will be provided at the Insured Organization's request as per the description of services attached to this endorsement. Post Breach Remedial Services will be considered Breach Response Costs, and will be available in response to incidents in which forensic costs covered under parts 2. and 3. of the definition of Breach Response Costs have been incurred, subject to the applicable Retention. Post Breach Remedial Services will not include any costs to purchase or upgrade any hardware or software. To access the Post Breach Remedial Services, the Insured Organization must: 1. notify the Beazley Breach Response Services Team via email at: bbr.claims(@beazley.com or via a toll-free 24-Hour Hotline: (866) 567-8570 following any actual or reasonably suspected Unauthorized Access or Use of the Insured Organization's Computer Systems so that the Beazley Breach Response Services Team can work with the Insured Organization to coordinate the provision of services from Beazley Service Providers; 2. notify the Underwriters that they desire to receive such services; and 3. enter into an engagement agreement with Lodestone to receive such service, within sixty (60) days following a determination of the actual Unauthorized Access or Use of the Insured Organization's Computer Systems, For purpose of this Endorsement, "Beazley Service Providers" means the Underwriters' network of third party breach response service providers listed at www.beazley.com/cyberservices that are to be utilized exclusively in response to incidents in which forensic costs covered under parts 2. and 3. of the definition of Breach Response Costs have been/will be incurred, subject to the applicable Retention. All other terms and conditions of this Policy remain unchanged. i Authorized Representative E12716 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" CRISIS MANAGEMENT EXPENSE COVERAGE This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The Limits listed in the Declarations under COVERAGE SCHEDULE are amended to include: Crisis Management Expenses: $1,000,000 2. INSURING AGREEMENTS is amended to include the following: To indemnify the Named Insured for 100% of the costs of a public relations consultancy incurred by the Insured Organization with Underwriters' prior written consent, for the purpose of averting or mitigating material damage to the Insured Organization's reputation that results or reasonably will result from a Claim covered under by the Policy and publicized through any media channel ("Crisis Management Expenses"); provided, this coverage shall only apply when covered Damages other than (crisis management expenses) exceeds the applicable Retention. 3. The definition of Damages is amended to include Crisis Management Expenses. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12864 Pagel of 1 042019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" CRYPTOJACKING ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The aggregate sublimit applicable to all loss under this endorsement is USD $100,000. 2 The Retention applicable to each incident, event, or related incidents or events, giving rise to an obligation to pay loss under this endorsement shall be USD $5,000. 3. INSURING AGREEMENTS is amended to include: Cryptojacking To indemnify the Insured Organization for any direct financial loss sustained resulting from Cryptojacking that the Insured first discovers during the Policy Period. 4. DEFINITIONS is amended to include: Cryptojacking means the Unauthorized Access or Use of Computer Systems to mine for Digital Currency that directly results in additional costs incurred by the Insured Organization for electricity, natural gas, oil, or internet(the "Utilities"); provided, however, that such additional costs for the Utilities are: 1. incurred pursuant to a written contract between the Insured Organization and the respective utility provider, which was executed before the Cryptojacking first occurred; 2. billed to the Insured Organization by statements issued by the respective utility provider, which include usage or consumption information; 3. not charged to the Insured Organization at a flat fee that does not scale with the rate or use of the respective utility; and 4. incurred pursuant to statements issued by the respective utility provider and due for payment during the Policy Period. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12972 Page 1 of 1 052019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" REPUTATION LOSS This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. Limit listed in the Declarations under COVERAGE SCHEDULE is amended to include: Reputation Loss: USD $1,000,000 2. Retention listed in the Declarations underCOVERAGE SCHEDULE is amended to include: Each incident giving rise to Reputation Loss: USD $5,000 3. INSURING AGREEMENTS is amended by the addition of: Reputation Loss To indemnify the Insured Organization for Reputation Loss that the Insured Organization sustains solely as a result of an Adverse Media Event that occurs during the Policy Period, concerning: 1. a Data Breach, Security Breach, or Extortion Threat that the Insured first discovers during the Policy Period; or 2. if this policy is a Renewal, a Data Breach, Security Breach, or Extortion Threat that the Insured first discovers during the last 90 days of the prior policy period. 4. DEFINITIONS is amended to include: Adverse Media Event means: 1. publication by a third party via any medium, including but not limited to television, print, radio, electronic, or digital form of previously non-public information specifically concerning a Data Breach, Security Breach, or Extortion Threat; or 2. notification of individuals pursuant to part 4. of the Breach Response Costs definition. Multiple Adverse Media Events arising from the same or a series of related, repeated or continuing Data Breaches, Security Breaches, or Extortion Threats, shall be considered a single Adverse Media Event, and shall be deemed to occur at the time of the first such Adverse Media Event. Claims Preparation Costs means reasonable and necessary costs that the Named Insured incurs to contract with a third party to prepare a proof of loss demonstrating Reputational Loss. E13040 Page 1 of 3 062019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Protection Period means the period beginning on the date the Adverse Media Event occurs, and ends after the earlier of: 1. 180 days; or 2. the date that gross revenues are restored to the level they would have been but for the Adverse Media Event. Renewal means an insurance policy issued by the Underwriters to the Named Insured for the policy period immediately preceding this Policy Period that provides coverage for a Data Breach, Security Breach, or Extortion Threat otherwise covered under this Policy. Reputation Loss means: 1. the net profit or loss before interest and tax that the Insured Organization would have earned during the Protection Period but for an Adverse Media Event; and 2. continuing normal operating expenses incurred by the Insured Organization (including payroll), but only to the extent that such operating expenses must necessarily continue during the Protection Period. When calculating any Reputation Loss, due consideration will be given to any amounts made up during, or within a reasonable time after the end of, the Protection Period. Reputation Loss will not mean and no coverage will be available under this endorsement for any of the following: (i) loss arising out of any liability to any third party; (ii) legal costs or legal expenses of any type; (iii) loss incurred as a result of unfavorable business conditions; (iv) loss of market or any other consequential loss; (v) Breach Response Costs; or (vi) Cyber Extortion Loss; There will be no coverage available under this endorsement if there is an actual interruption of the Insured Organization's business operations for any period of time. 5. Limits of Liability under LIMIT OF LIABILITY AND COVERAGE is amended to include: Reputational Loss and Claims Preparation Costs covered under this Policy arising from an Adverse Media Event concerning any Data Breach, Security Breach, or Extortion Threat (including a series of related, repeated or continuing Data Breaches, Security Breaches, or Extortion Threats) first discovered during the last 90 days of the prior policy period, will be considered to have been noticed to the Underwriters during the prior policy period and will be subject to the Policy Aggregate Limit of Liability of the prior policy period. Under such circumstances, if the Policy Aggregate Limit of Liability of the prior policy period is exhausted due to payments made under the prior policy, the Underwriter's obligation to pay Reputational Loss or Claims Preparation Costs under this Policy shall be completely fulfilled and extinguished. E13040 Page 2 of 3 062019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 6. Notice of Claim or Loss under GENERAL CONDITIONS is amended to include: With respect to Reputation Loss, the Named Insured must notify the Underwriters through the contacts listed for Notice of Claim, Loss or Circumstance in the Declarations as soon as practicable after discovery of the circumstance, incident or event giving rise to such loss. All Reputation Loss must be reported, and all proofs of loss must be provided, to the Underwriters no later than four (4) months after the end of the Protection Period. 7. This Policy will cover up to USD 50,000 of Claims Preparation Costs in excess of the Retention stated in Section 2. of this endorsement. All other terms and conditions of this Policy remain unchanged. Authorized Representative E13040 Page 3 of 3 062019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" STATE CONSUMER PRIVACY STATUTES ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that: 1. The Policy is amended to include the following insuring agreement: State Consumer Privacy Statutes To pay Penalties and Claims Expenses which the Insured is legally obligated to pay because of any Regulatory Proceeding first made against any Insured during the Policy Period for a violation of the California Consumer Privacy Act or any similar state statutes or state regulations specifically governing the Insured Organization's collection, use, disclosure, sale, processing, profiling, acquisition, sharing, maintenance, retention or storage of or provision of access to personal information or personal data as defined under the California Consumer Privacy Act or similar state statutes or state regulations. 2. The definition of Claim is amended to include institution of a Regulatory Proceeding against any Insured under the State Consumer Privacy Statutes insuring agreement for a violation of the California Consumer Privacy Act or any similar state statutes or state regulations specifically governing the Insured Organization's collection, use, disclosure, sale, processing, profiling, acquisition, sharing, maintenance, retention or storage of or provision of access to personal information or personal data as defined under the California Consumer Privacy Act or similar state statutes or state regulations. 3. The Governmental Actions exclusion will not apply to the State Consumer Privacy Statutes insuring agreement. 4. Solely with respect to the State Consumer Privacy Statutes insuring agreement, the Deceptive Business Practices, Antitrust & Consumer Protection exclusion is deleted in its entirety and replaced with the following: Deceptive Business Practices and Consumer Protection any actual or alleged false, deceptive or unfair trade practices, unfair competition, or violation of consumer protection law; but this exclusion will not apply to coverage under the State Consumer Privacy Statutes insuring agreement, provided no member of the Control Group participated in or colluded in the activities or incidents giving rise to coverage under such insuring agreement; Antitrust any actual or alleged antitrust violation, restraint of trade, false, deceptive or misleading advertising, violation of the Sherman Antitrust Act, the Clayton Act, or the Robinson-Patman Act, or inaccurate cost estimates or failure of goods or services to conform with any represented quality or performance; E13373 Pagel of 2 092019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 All other terms and conditions of this Policy remain unchanged. t Authorized Representative E13373 Page 2 of 2 092019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" EMPLOYEE DEVICE ENDORSEMENT This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that the definition of Computer Systems is amended to include computers, any software residing on such computers and any associated devices or equipment (including but not limited to wireless or mobile devices), operated by any person listed in parts 2., 3. or 4. of the Insured definition, but only for work done while acting within the scope of his or her employment and related to the conduct of the Insured Organization's business. All other terms and conditions of this Policy remain unchanged. Authorized Representative E13916 052020 ed. Page 1 of 1 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Effective date of this Endorsement: 03-Jul-2021 This Endorsement is attached to and forms a part of Policy Number: VG00003589AB Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters" VOLUNTARY SHUTDOWN COVERAGE This endorsement modifies insurance provided under the following: Beazley MediaTech In consideration of the premium charged for the Policy, it is hereby understood and agreed that the definition of Security Breach is deleted in its entirety and replaced with the following: Security Breach means: 1. A failure of computer security to prevent: (i) Unauthorized Access or Use of Computer Systems, including Unauthorized Access or Use resulting from the theft of a password from a Computer System or from any Insured; (ii) a denial of service attack affecting Computer Systems; (iii) with respect to coverage under parts 3. and 4. of the Media, Tech, Data & Network Liability insuring agreement, the Regulatory Defense & Penalties insuring agreement, and the Payment Card Liabilities & Costs insuring agreement, a denial of service attack affecting computer systems that are not owned, operated or controlled by an Insured; or (iv) infection of Computer Systems by malicious code or transmission of malicious code from Computer Systems; or 2. Solely with respect to the Business Interruption insuring agreement: (i) the voluntary and intentional shutdown of Computer Systems by the Insured Organization, with the Underwriters' prior consent, but only to the extent necessary to limit the Loss resulting from a situation described in 1.(i)or 1.(iv) above; or (ii) the intentional shutdown of Computer Systems by the Insured Organization as expressly required by any federal, state, local or foreign governmental entity in such entity's regulatory or official capacity resulting from a situation described in 1.(i) or 1.(iv) above. All other terms and conditions of this Policy remain unchanged. Authorized Representative E12300 Page 1 of 1 022019 ed. DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Attachment D-DigitalLearn-Building Your Own DigitalLearn Site Handout 2021 Pubt'IcLibrary ASSOC IATIO N Building Your Own DigitalLearn Site: Next Steps for Interested Libraries OLDIGITALLEARN .ORG is 6 A PLA INITIATIVE CONTACT INFORMATION Scott G.Allen, MS, Deputy Director Public Library Association 225 S. Michigan Avenue, Suite 1300 Chicago, IL 60611 312.280.5858 or sallen@ala.org 1 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 History of DigitalLearn IMLS grant to develop and launch website `0 Website and first Learn courses launched Promotion,development of Teach community --]New funding partners and new features 'DIGITAL ORG The need for increased digital literacy skills in the community, and the potential for public libraries to help communities in this area, led PLA to develop Digital Learn.org. PLA was awarded a two-year grant from the Institute of Museum and Library Services in the fall of 2012 to develop DigitalLearn.org. We hired Anneal Inc. out of Denver, Colorado to develop the strategy and manage the technology, and Kixal, a training and instructional design firm, to develop the courses. And of course, we consulted our public library members about what they wanted to see in the product— not just in terms of topics, but in terms of education and literacy level of the learner, length of the courses, and other features that would make sure it met the public library's needs. With so many digital literacy training resources out there, we wanted to make sure our product worked best for public libraries and their patrons needing help. The website was launched in summer 2013, featuring what was the 14 core courses under the banner "Learn" In 2014, we added the "Teach" section, which is a community of practice for digital literacy trainers and others teaching computer skills to share resources. As DigitalLearn was developed, we've had a Digital Learn.org Partners number of partners. Core funding from IMLS helped us develop the program, and the Chief O PublitLibrary .;:;;..t,MuseumINSTITUTE' s dLibrary ASSOCIATION SERVICES Officers of State Library Agencies and the ALA Office for Information Technology Policy were C00A cU t collaborators in its initial development. More recently, the ALA Office for Diversity, Literacy ALA Office for Diversity, and Outreach Services is supporting Literacy and Outreach Services development of new courses and other n n_ enhancements, and we are collaborating with the Chicago Public Library to add new and exciting features. 2 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9O36E703739 These are over 20 modules ranging from 6 to Digital Learn.org Content 22 minutes each. PLA intentionally started with very basic, critical skills. We know these are Why Use a Computer? Intro to Microsoft Word Getting Started on the Creating Resumes entry points for using a computer, and once Computer Online Job Searching these skills are established, it's easier for you Using a PC(Windows 7) Online Scams to help your patrons do what they really need Using PC(Windows 10) Internet Privacy Using A Mac(OS X) Cloud Storage to do with computers and the Internet. Basic Search Intro to Facebook Navigating a Website Buying a Plane Ticket Accounts and Passwords Intro toSkype We intentionally kept the length of each lesson Intro to Email Online Scams short based on what we knew learners needed Intro to Email(Part 2) 111111DIGITALLEARN.ORG and based on feedback of what worked best .• q PLA INITIATIVE for public libraries. We also wrote every course at the 4th grade reading level, with a few exceptions, since some computer terms do not go below about the 6th grade reading level. The courses are also mostly mobile-device friendly, although there are some lessons (for instance as you see on the screen, using the mouse) that do not translate to mobile devices. .NIGITALLEARN.ORG 2. I'm Overwhelmed! Why Use a Computer? "I want to get online,but I'm oveminelmedl" [�3 A&Vitles O 15 Minutes +Beginner MEN n� Q 17. .. .. When a learner opens a module, they will see very clearly how many lessons there are, what they cover, and how long they are. Each module is a video with narration. Users can also access the course transcript as a PDF under supplemental materials—this includes the entire text of the module and screen shots. Later in 2016, PLA will be adding subtitles to the courses, which may help users if they are somewhere where they cannot play audio or don't have headphones. The majority of courses are also available in Spanish, and PLA translates new courses as they are developed. Since launching the site, the most popular classes have been Getting Started on a Computer, Using a PC, Intro to Email, Basic Search and Navigating a Website. According to our feedback survey results, 73% of respondents said they used Digital Learn.org to learn how to use a computer, and 80% of the learners also stated that they learned a new skill through the site. 3 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 PLA and Chicago Public Library • CPL reviewed 36 online tools, narrowed it to 3 and conducted user testing in branches • DL was chosen —Met user needs for level, amount of text, etc. — Did not track user data, support custom features • CPL Foundation supported PLA to customize DigitalLearn with intent to spread to others ' DIGITAL ORG Thanks to a partnership with Chicago Public Library, PLA can now build customized DigitalLearn sites for public libraries across the country. CPL collected information about 36 different curricula and online tools teachers were using. CPL mapped these widely accepted competencies to the tools their instructional designer reviewed and narrowed our focus to just those freely available online and aligned with these competencies. Self-assessment surveys in libraries throughout the city confirmed that very few CPL learners are confident with these essential skills: • Basic computer productivity: (e.g., move the mouse, open a file, create a folder, etc.) 36% • Basic Internet skills: (e.g., search, download, upload, and send information online) 36% • Basic online productivity: (e.g., create and manipulate spreadsheets, create presentations, etc.) 28% • Intermediate computer productivity: (e.g., use of online services such as job applications, health services, banking, etc.) 21% Through several weeks of user testing different training programs, DL was preferred by both instructors and learners over the other 2 tested tools, which led to the decision to work with PLA and the DL design team to tweak and customize the tool to meet CPL patrons' needs. 4 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Why Build a Digitall-earn Site? Libraries can: Learners get: • Immediately access new DL • Targeted content that content from PLA develops basic but critical • Edit elements of PLA skills courses • Self directed courses they — Titles, descriptions can complete anytime, at — Post course resources the library or elsewhere • Create and easily post • Logins to save progress, custom course content retrieve certifications • Receive shared content • Recommendations and a from other libraries custom course list based on • Collect user analytics needs • Co-branding ODIGITALLEARN.ORG A PLA INITIATIVE So in collaboration with the Chicago Public Library, PLA developed a new, personalized interface for library systems to help them customize DigitalLearn and measure their impact in digital literacy training. PLA can make this personalized site available to other libraries across the country. Through this partnership, PLA and CPL have: • developed a branded point of entry to the courses for CPL • developed a user interface to create accounts, take needs assessments, and create and manage learning plans • created an administrative interface for CPL staff Core function improvements include the ability for learners to login/logout and retain their place, track achievements and courses completed, and establish learning goals. CPL will also be able to select which of PLA's modules they want to present through their portal and develop their own modules to post. For instance, they might work with Chicago Public Schools to develop training modules for parents with children in the schools about how to work with the school's websites. 5 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Customization Options Do It Yourself Basic Enhanced Customization Customization You use the open You work with PLA to You work with PLA to source materials to create your own site create your own site create your own site with a basic, with a level of predetermined level customization specific of customization to your needs SDIGITALLEARN.ORG IF u A PLA INITIATIVE PLA is offering libraries three options for building their own DigitalLearn sites. 6 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Do It Yourself Pros Cons • No fees/direct costs • Requires time and skills • Ability to host site of library IT staff anywhere • No analytics unless your • Your team can choose staff creates them to connect courses to • Ongoing management other library projects, of updates is up to you sites • No additional support or TA from PLA/Anneal ODIGITALLEARN.ORG ®• A PLA INITIATIVE The Do It Yourself option is best for libraries with sufficient IT staff and experience to set up and host the site, using the open source files. This can happen at any time and PLA doesn't need to be involved. Chicago Public Library - Digital Learn Ili o Install Dependencies RVM Posigresgi Redis Starting a new project using this template • Clone this project from Gil • Create a new gemset with Won gemset create cpldl'(assumes rvm is installed) • Run bundle install • Run rake db:migrate Up and Running. • Ruby version ruby 2.2.3 • Database creation rake db:create db:migrate ,ow to rvn the test suite github.com/PublicLibraryAssoc • F a rspec :testing suite o ruborop :for syntax and code smells o hrakeman :for security smells These are instructions on how to set up a customized DigitalLearn site by going to Github and replicating the Chicago Public Library site. 7 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Basic Customization Pros Cons • Low cost compared to • Fee required similar services • Only basic flexibility in • Doesn't burden IT staff customization or require special skills • Requires initial and • New features and ongoing commitments content shared of staff team automatically • No custom integrations • Fast build and test cycle with existing programs • Includes basic analytics or sites ODIGITALLEARN.ORG .w A PLA INITIATIVE Basic customization will be appropriate for most libraries because it is quick and easy, low cost compared to other subscription services, and easy to manage with whatever staff is available. More information on the cost and process follows. https://chipubiib.digitaIlearn.org/ IIIII® Use a computer to do almost ariyihing! ' DIGITALLEARN.ORG ®. A PLA INITIATIVE Basic customization will set up a site for your library similar to what is set up for Chicago Public Library. Visit https://chipublib.digitallearn.org/to see the CPL site. 8 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 https://chipublib.digitaIlearn .org/ r Use a computer to do almost anything' Creating ._ sumes Lop N 5ipn VA -�• �� [j4 Aclivites 021 Minutes -- + Beginner '� UU Mn M�wncoevM.e cwnu. novmmaRawrces CHICAGO ym.tr�5 ReneJ.m -au,.• L n.wn L n�.e1�=N LIBRAR PUBLICY a LIBRAR ODIGITALLEARN.ORG A PLA INITIATIVE Libraries setting up their own sites can decide which fields to require when users register (for instance, CPL has users affiliate with a branch) and can also post their own "post course" materials and additional resources for learners. 9 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 CPL Dashboard Apr — May 2016 Most Completed Courses How Sessions Initiated l� Top Referrers - p -- — Downloaded Reference Materials Sessions by City -M* Most Viewed Content ODIGITALLEARN.ORG .� A PLA INITIATIVE PLA will set up a Google Analytics site for the library's DigitalLearn site to show basic information such as how sessions were initiated, were people came from, which courses were accessed and completed, and which materials were downloaded. 10 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Admin Dashboard �Change Logln Information Digital Learn Courses pdate Profile OUrse These courses are aJfired byrses ha Zlpcotle) camplW—Rep.M�byubraryi Course Topic Language Import Usernccaun[s CMS pages 6nline Scams S—rhy EngIM Impurtcaurse Invite Admin 4DIGITALLEARr .ORG a Perhaps the most exciting features that PLA and Chicago Public Library have created are the "back end" features for administrators. We've made it very easy for the library to choose which courses to publish, edit course descriptions and other features, publish their own courses that meet local community needs, and get analytics to show funders and other stakeholders how many people at their branches are using the site and what they are learning. These are all features that PLA can help set up for other libraries. On this page, you see the basic Administrator Dashboard. From here, library staff can choose which courses the present on their personalized site, whether they come from PLA's DigitalLearn site, or they are new and developed by the library. Libraries can develop and post their own courses. Right now, course files must be in Articulate Storyline authoring software, which is what was used to develop DigitalLearn modules. In the future we expect to be able to allow posting of courses in other formats. By giving the library tools to develop and post their own courses, we can help libraries directly address specific community needs. These may be things like: • collaborating with the local school system on a course that helps parents learn to better use the school's online parent portal • Working with city government to develop training on using the city websites to apply for permits, pay bills, or access other services • simply translating content of basic computer or Internet courses into a language that's prominent in the local community 11 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Text copies of the course Additional Resources(post-completion) Upload any supporting documentation or supplemental materials Upload any supporting documentation or supplemental materials needed during the course. needed after the course. —No file chosen No file chosen (optional)Add a description for this attachment... I (optional)Add a description for this resource... Add Supplemental Attachment 1 Add Post Course Attachment Current Supplemental Attachments Current Post-Course Attachments Res'mepol.pdf Delete HowTOUseWordResumeTemplate.pcil Delete Resume_Lesson_1.pdf Delete Reaume'remplate.dua—Delete Resume_Lesson_2,pdf Delete Resume_Builder_user_Gllide,pdf—Delete Resume_Lesson_3.pdf Delete Resume_Lesson_4.pdf Delete Info to help learners practice and use their new skills(post completion) 0 �, B 1 (2 l -E fy -I I F—=t I—I Now Irs lime la cnata your mums.llaa the how to use a resurne Ieal hantloul W gel.laacb. H you al¢rtll eul2 flow 10 MM browse resume.amale.IO.I10,uoe tW nesame eu,li ih NB Illi0d5 wo 61 wabieto,ri,will neea to lollow tho o,"a...10 createa user name ar l passworb.After you have-latl an account,kg Into www.Illlrwlsworknel.coMResume antl look for the Resume eullol HIM. H you neat hat Impronig your re.uma,you may...d it to Meinfuse to gel leebback on hfir hea,You will noad your Chicago F,l llc Ubrery cau to no M.selvir.,3. Once you ham your resume featly,use a tc apply far Juba.Checkout bnl lob lieangs w the III mis—d a or take a course to learn howm search la lobs Onkne. Course Topics* Course Language* Course Format Information Searching English Desktop +)oh Search , Core Library staff can post supplemental materials to accompany the courses. They can post directions to the learners, for after they complete the course. We've called these "info to help learners practice and use their new skills." When PLA developed the personalized site for Chicago Public Library, the ability to post supplemental materials was very important. There were many city and community partners engaged in their efforts to help Chicago citizens develop computer skills and gain employment or otherwise participate more successfully in community life. These partners have their own programs to help people develop resumes, find employment, and more. These features on the personalized DigitalLearn site give library staff the ability to suggest to learners that they use their new skills to connect with a local social service agency, or use another city resource to find a job opening, or make an appointment for counseling—whatever is most appropriate for the library and its local partners. 12 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Online Job Searching Courses»Online Job Searching Use my skills now!(click each link below) Additional Resources Now that you know how to search for jobs online,checkout local ,y,Center_Working-Familiesmap.pdf job listings on the following websites: ,#,Job_Search_Organizer.pdf 1.illinois workNetJob Finder- arch by keyword and location. Nearby_Food_Servicejobs.pdf 2.1000 Jobs-Search manufacturing jobs. 3.Government Jobs-Search opportunities by salary and more. Lac centers ......,o.o..,.,.� . ,,. Find local centers to help you look and apply for jobs at the Chicago °::�:b�� ook Workforce Partnerships. J" =�"�+•"-a—"R+^"�+"'��� OrvlsittiDisability or ore guidance onyourjob search. Other online job-search sites Indeed.com-One of the most popular job-search sites.You can search by city,state,or zip code and narrow the results down by salary,job type,title,and other filters.If you create an account, you ca save your searches for later use. DIGITALLEARN.ORG 0 A PLA INITIATIVE This is an example of what Chicago Public Library has added to DigitalLearn to help job seekers practice their skills and advance in their job hunt, after completing the Online Job Searching course. For instance, they encourage learners to check out local job listings on the "Illinois workNet Job Finder" site. They also refer learners to local centers to help them look and apply for jobs—such as the Chicago Cook Workforce Partnership web site. They've also posted PDFs with important local information, such as nearby businesses in food service that are almost always hiring. 13 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Basic Customization Timeline Libraries opting for the basic customization will work with PLA over a four week period to develop their sites. PERIOD ACTIVITY Pre Work PLA provides library with instruction on preparing logo, palette, copy for editable sections, desired fields for user info, etc. Library identifies staff team and compiles initial information. Week 1 PLA, development team, and library meet virtually to review timeline, roles, analytic needs, and collected materials. Week 2 Development team builds customized site. Library team is available as needed for questions and additional information. Site review meeting is held at end of week. Week 3 Library team reviews and tests site and provides feedback and questions to PLA. Corrections and tweaks to customization are possible, but requests for new site content or functionality may require an additional contract for enhanced customization. ' Week 4 Final changes are made, analytics go live, and site is launched. PLA provides staff team with short virtual training on analytics and any other features not yet covered. Post Development Updates and fixes to site automatically pushed out. New content is pushed out and library must edit, approve and publish. Bugs/errors reported to PLA for action. Requests for new features or enhanced customization considered by PLA on case- by-case basis. Most will require new contract, but suggestions that improve functionality of all DL sites may be accommodated by PLA. 14 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Enhanced Customization Pros Cons • All the features of basic • Cost may be substantial customization and more • Timeline may be long • Can integrate directly • Requires substantial into other initiatives commitment of library • Can include support staff team such as training, • May require ongoing marketing, etc. contract to maintain UDIGITALLEARN.ORG .11 A PLA INITIATIVE PLA and its contractors are available to work with libraries to develop other features for their DigitalLearn sites on a case-by-case basis. PLA will meet with the library staff to assess their needs and develop a proposal for how the site can be adapted. 15 DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739 Costs • Do It Yourself: no cost • Basic Customization — $15,000 fee to PLA for initial build, 4-week period of development and testing, basic training, and launch • Enhanced Customization: — Cost TBD based on needs • Other Services — Staff training may be arranged separately (on authoring software, analytics, marketing, stakeholder engagement, assessing learner needs, measuring success) DIGITALLEARN.ORG • A PLA INITIATIVE The $15,000 cost for basic customization includes development and one year of hosting. A hosting fee will be required annually after the first year, and may cost$600-$1,500 (costs will be determined by the number of sites built, and will go down as additional sites are developed). 16