HomeMy WebLinkAbout2022-077-E-IT Dept-PUBLIC LIBRARY ASSOCIATION, a divison of the American Library Association-Digital learning DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
[Departmental Use Only]
TITLE
FY
NORTH CAROLINA
SERVICES AGREEMENT NO RFP/RFQ
ORANGE COUNTY
This Services Agreement (hereinafter "Agreement"), made and entered into this 15 day of
February, 2022, ("Effective Date") by and between Orange County, North Carolina a political
subdivision of the State of North Carolina (hereinafter, the "County") and the American Library
Association, an Illinois not-for-profit corporation, acting by and through its Public Library
Association Division, 50 E. Huron St., Chicago, IL 60611, (hereinafter, the "Provider").
WITNESSETH:
That the County and Provider,for the consideration herein named,do hereby agree as follows:
1. Services
a. Scope of Work.
i) This Agreement is for services to be rendered by Provider to County with respect to
(insert type of project): DigitalLearn.org is an online resource which builds upon and
fosters the work of libraries and community organizations as they work to increase
digital literacy across the nation. Included in DigitalLearn.org is a collection of self-
directed tutorials for end-users to increase digital literacy, as well as a community of
practice for public library-based digital literacy trainers to share resources, tools and
best practices. CKD Technology Partners serves as a subcontractor for the Provider
in maintaining the DigitalLearn platform.
ii) By executing this Agreement, the Provider represents and agrees that Provider is
qualified to perform and fully capable of performing and providing the services
required or necessary under this Agreement in a fully competent, professional and
timely manner.
iii) Time is of the essence with respect to this Agreement.
iv) The services to be performed under this Agreement consist of Basic Services, as
described and designated in Section 3 hereof. Compensation to the Provider for
Basic Services under this Agreement shall be as set forth herein.
2. Responsibilities of the Provider
a. Services to be provided. The Provider shall provide the County with all services required
in Section 3 to satisfactorily complete the Project within the time limitations set forth
herein and in accordance with the highest professional standards.
b. Standard of Care.
Revised 06/21 012822
1
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
i) The Provider shall exercise reasonable care and diligence in performing services
under this Agreement in accordance with the highest generally accepted standards
of this type of Provider practice throughout the United States and in accordance
with applicable federal, state and local laws and regulations applicable to the
performance of these services. Provider is solely responsible for the professional
quality, accuracy and timely completion and submission of all work related to the
Basic Services.
ii) Provider shall be responsible for all errors or omissions of its agents, contractors,
employees, or assigns in the performance of the Agreement. Provider shall correct
any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at
no additional cost to the County.
iii) The Provider shall not, except as otherwise provided for in this Agreement,
subcontract the performance of any work under this Agreement without prior
written permission of the County. No permission for subcontracting shall create,
between the County and the subcontractor, any contract or any other relationship.
iv) Provider is an independent contractor of County. Any and all employees of the
Provider engaged by the Provider in the performance of any work or services
required of the Provider under this Agreement, shall be considered employees or
agents of the Provider only and not of the County, and any and all claims that may
or might arise under any workers compensation or other law or contract on behalf
of said employees while so engaged shall be the sole obligation and responsibility
of the Provider.
v) If activities related to the performance of this Agreement require specific licenses,
certifications, or related credentials Provider represents that it or its employees,
agents and subcontractors engaged in such activities possess such licenses,
certifications, or credentials and that such licenses certifications, or credentials are
current, active, and not in a state of suspension or revocation.
vi) In determining the Basic Services to be provided, should any documents be
referenced in this Agreement,the terms of this Agreement shall have priority in any
conflict between the terms of referenced documents and the terms of this
Agreement.
vii) Should this Agreement involve project designs, the construction or creation of
which is to be bid out or fulfilled by other contractors, and bidding or negotiation
with contractors produce prices which, when added to the other elements of the
approved total project cost, produce a cost that is in excess of the approved total
project cost,the Provider shall participate with the County in negotiation and design
adjustments to the extent such are necessary to obtain prices within the approved
total project cost. All activity of the Provider with respect to these matters shall
constitute Basic Services and shall be performed by the Provider without additional
compensation. If negotiation and design adjustments fail to bring costs within the
total project cost the County may reject all bids and Provider will redesign or reduce
portions of the project in an effort to reduce the bid prices to within the total project
cost and rebid the project. One such redesign is included within Basic Services. If
Revised 06/21 012822
2
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
this second letting for bids does not produce bids that are within the approved total
project cost initially or after negotiations with the contractor the cost is not reduced
to an amount within the total project cost, the Provider is not obligated to engage
in further redesign.
3. Basic Services
a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows
(fully describe services to be provided): Refer to (i) Attachment A - DigitalLearn -
Agreement for Services, (ii) Attachment B- DigitalLearn - Cloud Questionnaire, (iii)
Attachment C - DigitalLearn - Cyber Liability Questionnaire_Digital Learning Cyber
Policy, (iv)Attachment D-DigitalLearn-Building Your Own DigitalLearn Site Handout
2021
4. Duration of Services
a. Term. The term of this Agreement shall be from February 1, 2021 to June 30, 2023
b. Scheduling of Services.
i) The Provider shall schedule and perform its activities in a timely manner.
ii) Should the County determine that the Provider is behind schedule, it may require
the Provider to expedite and accelerate its efforts, including providing additional
resources and working overtime,as necessary,to perform its services in accordance
with the approved project schedule at no additional cost to the County.
iii) The Commencement Date for the Provider's Basic Services shall be 2/15/2022.
5. Compensation
a. Compensation for Basic Services. Compensation for Basic Services shall include all
compensation due the Provider from the County for all services satisfactorily (as
determined by the County)performed pursuant to this Agreement. The maximum amount
payable for Basic Services shall not exceed fifteen thousand Dollars ($15,000.00).
Payment for satisfactorily performed Basic Services shall become due and payable within
thirty (30) days of Provider properly invoicing County. Payment shall be subject to
provisions of Section 5(b).
b. Disputes. In the event the amount stated on an invoice is disputed by the County, the
County may withhold payment of all or a portion of the amount stated on an invoice until
the parties resolve the dispute. Should Provider fail to perform its duties under the terms
of this Agreement,County may,without fault or penalty,withhold any payment associated
with the work to be performed until such time as said work is completed.
c. Additional Services. County shall not be responsible for costs related to any services in
addition to the Basic Services performed by Provider unless County requests such
additional services in writing and such additional services are evidenced by a written
amendment to this Agreement.
Revised 06/21 012822
3
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
6. Responsibilities of the County
a. Cooperation and Coordination. The County has designated (Erin Sapienza) to act as the
County's representative with respect to the Project who shall have the authority to render
decisions within guidelines established by the County Manager or the County Board of
Commissioners and who shall be available during working hours as often as may be
reasonably required to render decisions and to furnish information.
7. Insurance
a. General Requirements. Provider shall obtain, at its sole expense, Commercial General
Liability Insurance, Automobile Insurance, Workers' Compensation Insurance, and any
additional insurance as may be required by County's Risk Manager as such insurance
requirements are described in the Orange County Risk Transfer Policy and Orange
County Minimum Insurance Coverage Requirements (each document is incorporated
herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing division/contracts.php). If
County's Risk Manager determines additional insurance coverage is required such
additional insurance shall consist of N/A (if no additional insurance required mark N/A
as being not applicable). Provider shall not commence work until such insurance is in
effect and certification thereof has been received by the County's Risk Manager.
8. Indemnity
a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without
limitation, to defend, indemnify and hold harmless the County from all loss, liability,
claims or expense, including attorney's fees, arising out of or related to the Project and
arising from property damage or bodily injury including death to any person or persons
caused in whole or in part by the negligence or misconduct of the Provider except to the
extent same are caused by the negligence or willful misconduct of the County. It is the
intent of this provision to require the Provider to indemnify the County to the fullest extent
permitted under North Carolina law.
9. Amendments to the Agreement
a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional
compensation or a change in duration of this Agreement shall be made by a written
Amendment to this Agreement executed by the County and the Provider. The Provider
shall proceed to perform the Services required by the Amendment only after receiving a
fully executed Amendment from the County.
10. Termination
a. Termination for Convenience of the County. This Agreement may be terminated without
cause by the County and for its convenience upon seven (7) days' prior written notice to
the Provider.
b. Other Termination. The Provider may terminate this Agreement based upon the County's
Revised 06/21 012822
4
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
material breach of this Agreement; provided, the County has not taken all reasonable
actions to remedy the breach. The Provider shall give the County seven (7) days'prior
written notice of its intent to terminate this Agreement for cause. Either party may
terminate this Agreement upon notice to the other party that obligations pursuant to this
Agreement are made impractical due to declarations of emergency by Orange County or
by North Carolina due to events directly impacting Orange County. Both parties shall
remain responsible for all payment and performance due up to the receipt of such notice,
but shall have no further obligation or responsibility beyond that date provided the
terminating party has taken all reasonable steps to complete the performance of its
obligations.
c. Compensation After Termination.
i) In the event of termination, the Provider shall be paid that portion of the fees and
expenses that it has earned to the date of termination, less any costs or expenses
incurred or anticipated to be incurred by the County due to errors or omissions of
the Provider. Upon request of the County, the Provider shall submit to County all
relevant documentation, including but not limited to,job cost records, to support its
claims for final compensation.
ii) Should this Agreement be terminated, the Provider shall deliver to the County
within seven(7)days, at no additional cost, all deliverables including any electronic
data or files relating to the Project.
d. Waiver. The payment of any sums by the County under this Agreement or the failure of
the County to require compliance by the Provider with any provisions of this Agreement
or the waiver by the County of any breach of this Agreement shall not constitute a waiver
of any claim for damages by the County for any breach of this Agreement or a waiver of
any other required compliance with this Agreement.
e. Suspension. County may suspend the Basic Services and this Agreement at any time for
County's convenience and without penalty to County upon three (3) days' notice to
Provider. Upon any suspension by County, Provider shall discontinue work on the Basic
Services and shall not resume the Basic Services until notified to proceed by County.
11. Additional Provisions
a. Limitation and Assignment. The County and the Provider each bind themselves, their
successors, assigns and legal representatives to the terms of this Agreement. Neither the
County nor the Provider shall assign or transfer its interest in this Agreement without the
written consent of the other.
b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights
of respective parties hereunder shall be governed by the laws of the State of North
Carolina. By executing this Agreement Provider affirms that Provider and any
subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter
64 of the North Carolina General Statutes. By executing this Agreement Provider
certifies that Provider has not been identified, and has not utilized the services of any
agent or subcontractor identified, on the list created by the State Treasurer pursuant to
Revised 06/21 012822
5
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not
been identified, and has not utilized the services of any agent or subcontractor identified,
on the list created by the State Treasurer pursuant to G.S. 147-86.81.
c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable
local, state, and federal laws, rules, and regulations including but not limited to all state
and federal non-discrimination laws, policies, rules, and regulations and the Orange
County Non-Discrimination Policy and Orange County Living Wage Policy (each policy
is incorporated herein by reference and may be viewed at
hqp://www.oran eg countync. og v/departments/purchasing division/contracts.php.) Any
violation of the Orange County Non-Discrimination Policy is a breach of this Agreement
and County may immediately terminate this Agreement without further obligation on the
part of the County. This paragraph is not intended to limit and does not limit the definition
of breach to discrimination.
d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with
respect to any provision of, or the performance or non-performance of, this Agreement
shall be brought in the General Court of Justice of North Carolina sitting in Orange
County, North Carolina. It is agreed by the parties that no other court shall have
jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be
initiated by either Party, however, the Parties may agree to nonbinding mediation of any
dispute prior to the bringing of such suit or action.
e. Entire Agreement. This Agreement represents the entire and integrated agreement
between the County and the Provider and supersedes all prior negotiations,representations
or agreements, either written or oral. This Agreement may be amended only by written
instrument signed by both parties. Modifications may be evidenced by facsimile
signatures.
f. Severability. If any provision of this Agreement is held as a matter of law to be
unenforceable, the remainder of this Agreement shall be valid and binding upon the
Parties.
g. Ownership of Work Product. Should Provider's performance of this Agreement generate
documents, items or things that are specific to this Project such documents,items or things
shall become the property of the County and may be used on any other project without
additional compensation to the Provider. The use of the documents,items or things by the
County or by any person or entity for any purpose other than the Project as set forth in this
Agreement shall be at the full risk of the County.
h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and the
validity of this Agreement is based upon the availability of public funding under the
authority of its statutory mandate.
In the event that public funds are unavailable or not appropriated for the performance of
County's obligations under this Agreement, then this Agreement shall automatically
expire without penalty to County immediately upon written notice to Provider of the
unavailability or non-appropriation of public funds.It is expressly agreed that County shall
not activate this non-appropriation provision for its convenience or to circumvent the
Revised 06/21 012822
6
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
requirements of this Agreement.
In the event of a change in the County's statutory authority, mandate or mandated
functions, by state or federal legislative or regulatory action, which adversely affects
County's authority to continue its obligations under this Agreement, then this Agreement
shall automatically terminate without penalty to County upon written notice to Provider
of such limitation or change in County's legal authority.
i. Si natures. This Agreement together with any amendments or modifications may be
executed electronically. All electronic signatures affixed hereto evidence the consent of
the Parties to utilize electronic signatures and the intent of the Parties to comply with
Article 11A and Article 40 of North Carolina General Statute Chapter 66.
j. Notices. Any notice required by this Agreement shall be in writing and delivered by
certified or registered mail, return receipt requested to the following:
Orange County Provider's Name
Attention:Erin Sapienza Attention:MaryDavisFournier
Public Library Association,
a division of the American Library Association
P.O. Box 8181 225 N Michigan Ave,Ste 1300
Hillsborough,NC 27278 Chicago, IL 60601
[SIGNATURE PAGE TO FOLLOW]
Revised 06/21 012822
_ 7
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have
hereunder set their hands and seal, all as of the day and year first above written.
ORANGE COUNTY: PROVIDER:
DocuSigned by: DocuSigned by:
L
50i.t,�.�c2/15/20222/15/2022
By: E 1-DFP.BP.BZ483 By.
Mary Davis Fournier
Executive Director, Public Library Association
Printed Name and Title
DocuSigned by:
By: -Q- Y°u 2/15/2022
1 D07F8EF4B8148E...
Tracie D. Hall, Executive Director,
American Library Association
Printed Name and Title
Revised 06/21 012822
_ 8
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
ORANGE COUNTY—DEPARTMENT USE ONLY
Party/Vendor Name: PUBLIC LIBRARY ASSOCIATION, a divison of the American Library Association
Party/Vendor Contact Person: Tracie D.Hall Contact Phone:312-280-5861 Party/Vendor Address: 225 N.Michigan
Ave. City Chicago State: IL Zip: 60601 Department: PLA Amount: Fifteen thousand dollars ($15000.00)
Purpose: Digital learning Budget Code(s):10500020-750150 Vendor#N/A Vendor is a BOCC consultant?Yes
❑ No®Contract Type: (Check one)New ®Renewal ❑Amendment ®'fective Date 02/15/2022 Approved by
Board Yes ❑No®Agenda Date:N/A---For Section XIV. c. contracts only,Approved by Board in Current FY
Budget Yes[—]No
This agreement is approved as to technical form and content and I as Department Director affirmatively state work on
this project has not been initiated p ' RvceJUaWthon of the agreement:
Department Director's Signatur Ems. "`I' Date:2/15/2022
Agreements for emergency services or repair are not subject to the above affirmation. If services related to this
agreement have already begun or been completed please briefly describe the nature of the emergency condition that
was addressed: N/A
Information Technologies
(Applicable only to hardware/software purchases or related services)This agreement has been reviewed and is
approved as to information technology co ^ cam�e�yifications:
JlKA 44ny 2/22/2022
Office of the Chief Information Officer, or Date:
Risk Management
This agreement is approved for sufficiencQ,tSa cbvvultb awnaw*:standards,specifications,and requirements:
Office of the Risk Management Office Date:2/22/2022
Financial Services
This instrument has been pre-audited i epfltd pLFquired by the Local Government Budget and Fiscal Control Act:
lq'�p '�"�" °'� 2/23/2022
Office of the Chief Financial Office ,awnCJ40Q Date:
Legal Services
This agreement is approved as to legal form and sufficiency:
Office of the County Attorney Date:
Clerk to the Board
Received for record retention:
All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov
The following signature block is for hard copies only and is not required for Docusign contracts:
Office of the Clerk to the Board Date:
Revised 06/21 012822
9
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
0 Pubiic Library Attachment A -DigitalLearn-Agreement for Services
ASSOCIATION 225 N. Michigan Ave, Ste 1300, Chicago, I L 60601
PUBLIC LIBRARY ASSOCIATION
225 N. Michigan Avenue, Suite 1300
Chicago, IL 60601
AGREEMENT FOR SERVICES
DigitalLearn.org Library Interface Development
THIS AGREEMENT FOR SERVICES ("Agreement") is entered into as of DATE
between the American Library Association, an Illinois not-for-profit corporation, acting by and
through its Public Library Association Division, 50 E. Huron St., Chicago, IL 60611 (the
"Association") and the Orange County Public Library, 137 W. MARGARET LANE
HILLSBOROUGH,NC 27278 ("Library").
1. SERVICES AND SOFTWARE IN GENERAL
The Association owns, hosts, updates periodically and manages connectivity to software
commonly identified and referenced herein as DigitalLearn.org. DigitalLearn.org is an online
resource which builds upon and fosters the work of libraries and community organizations as
they work to increase digital literacy across the nation. Included in DigitalLearn.org is a
collection of self-directed tutorials for end-users to increase digital literacy, as well as a
community of practice for public library-based digital literacy trainers to share resources, tools
and best practices. Wherever the term "DigitalLearn.org"is used herein it shall be deemed
interchangeable with"DigitalLearn."
The Association will provide project management, software, software enhancements, and
instructional design services resulting in a customized software interface ("Interface") for access
to DigitalLearn.org, which Interface shall be accessible at no cost(except for the fees set forth
herein)to the Library. The Association shall provide the Library with the Deliverables described
on Exhibit A, attached hereto and made a part hereof by this reference, during the term of the
Agreement (the "Deliverables").
2. COMPENSATION CLAUSES
The Library agrees to pay the Association a total of$15,000 for the Deliverables. The
Association will invoice the Library upon execution of the Agreement for an amount equal to
one half of the total budget($7,500) and will subsequently invoice the Library for the balance
($7,500) when both parties agree customization of the Interface is complete and the Library
makes the Interface accessible to learners, or"live."All invoices shall be paid by the Library
within thirty(30) days from the date of issue.
3. INDEMNITY
Each party hereby agrees to assume responsibility hereunder for the acts of its agents,
employees, officers or directors.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
4. STATUS OF THE ASSOCIATION
It is understood and agreed that the Association, its employees and its subcontractors are
not employees of the Library. Accordingly, the parties recognize and agree that the Library shall
have no authority to bind the Association in any contract. Any persons who act on behalf of the
Library shall be employees or agents solely of the Library and not of the Association.
5. OWNERSHIP OF WORKPRODUCT, GRANT OF LICENSE AND SOURCE CODE
Subject to any rights expressly conferred herein upon Library, Association shall retain
any and all right, title and interest, including all copyright, patent, trademark, and trade secret
rights, which may arise from the Association's performance pursuant to this Agreement. All
Deliverables, including all intellectual property rights contained therein and associated with
DigitalLearn.org and provided to the Library as a part of the services under this Agreement shall
be owned exclusively by the Association, including but not limited to: (a)work papers, subject
code, object code, computer files, proprietary information, processes, methodologies, know how,
tools, devices and software; and(b) any modifications, alterations, enhancements, extensions,
applications, forms, configurations or derivative works made to the software, excepting only
such work papers, subject code, object code, computer files, proprietary information, processes,
methodologies, know how, tools, devices and software and/or modifications, alterations,
enhancements, extensions, applications, forms configurations or derivative works made to the
software solely by Library(collectively referred to herein as "Association Property").
Association Property includes such information as existed prior to the delivery of services and, to
the extent such information is of general application, anything which the Association may
discover, create or develop during provision of services to the Library.
To the extent that the Deliverables contain Association Property, the Association hereby
grants to Library a fully-paid-up, non-exclusive, nontransferable,perpetual license to the
Association Property as part of the Deliverables for its business purposes. The Association
warrants that it has the right to grant the rights to the Association Property including to the
Deliverables. The Association Property or Deliverables may not otherwise be disclosed,
published or used in whole or in part for any other purpose.
Except as otherwise expressly provided herein, neither party shall by reason of this
Agreement or its performance obtain any right, title, license or other interest, either express or
implied, to the other party's intellectual property. Library hereby agrees not to sell the
Association Property, Deliverables or work product created by Association for the benefit of
Library pursuant to this Agreement.
The Association shall be responsible for software support obligations, in its reasonable
discretion, for DigitalLearn.org for so long as the Association has requisite funding to fulfill such
support obligations and determines it is in its best interest to do so but in no case shall such
support obligations terminate before August 31, 2022.
The Library agrees that it shall execute any and all documents necessary to release to the
Association any and all rights which the Library may acquire in any property, whether tangible
or intangible, in direct connection with the Library's performance pursuant to this Agreement.
6. CONFIDENTIALITY
2
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Unless required by law, the Library and its employees and agents shall not, during the
term of this Agreement, or at any time thereafter, disclose any information acquired by the
Library pursuant to this Agreement to any third party except as permitted, in writing, by the
Association.
7. NONCOMPETITION CLAUSE
The Library agrees not to market or sell to members of the Association, any products or
services similar to those covered by this Agreement.
8. WARRANTY
Association warrants that Association's services will be performed with reasonable care
in a diligent and competent manner. Association's sole obligation will be to correct any non-
conformance with this warranty, provided that Library gives Association written notice within 30
days after the services are performed or delivered, whichever comes first. The notice will
specify and detail the non-conformance and Association will have a reasonable amount of time,
based on its severity and complexity, to correct the non-conformance. This warranty is
Association's only warranty concerning the services and any Deliverable, and is made expressly
in lieu of all other warranties and representations, express or implied, including any implied
warranties of merchantability, or fitness for a particular purpose, non-infringement, any implied
warranties arising out of association's trade, dealing, or performance or otherwise, all of which
are hereby disclaimed.
Association will not be liable for any special, consequential, incidental, indirect or
exemplary damages or loss (nor any lost profits, savings or business opportunity). Further,
Association's liability relating to this Agreement, DigitalLearn.org and any use thereof will in no
event exceed an amount equal to the fees (excluding taxes and expenses, if any) Association
receives from Library pursuant to this Agreement. Neither party will be liable for any delays or
failures in performance due to circumstances beyond its reasonable control.
9. TERMINATION
The term of this Agreement shall be from the Effective Date to DATE except in reference
to support obligations, which obligations shall terminate on DATE or such later date as is
mutually agreed upon.
This Agreement may be terminated by either party upon the material breach of this
Agreement by the other party or the negligent, fraudulent or criminal act or omission of the other
party in the performance of its obligations under this Agreement. Upon termination or expiration
for any reason, the Library shall immediately return to the Association all materials issued for its
use pursuant to this Agreement. In the event of termination by Library, the Library shall have no
further obligation to remit payments to Association,provided nothing herein shall be deemed to
be a waiver of such other rights Library may have at law or equity. These obligations will
survive the termination of this Agreement and shall remain in full force and effect.
10. NOTICES
3
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
All notices and other communications required or permitted under this Agreement shall
be in writing and may be personally delivered, telecopied or sent by first-class mail, postage
prepaid, to the parties at their addresses as shown from time to time on the records of the
Association. Any party may specify a different address by notifying the Association in writing of
such different address. All notices and other communications required or permitted under this
Agreement shall be deemed to have been received on the day when personally delivered,
telecopied, or three days after being mailed, as the case may be.
11. MISCELLANEOUS
A. This Agreement shall be governed by the laws of the State of Illinois, and all
questions pertaining to the validity or construction of this Agreement shall be
determined in accordance with the internal laws of the State of Illinois without
regard to conflict of laws principles.
B. There are no oral understandings between the parties to this Agreement. No
modification or waiver of any provision of this Agreement shall be valid unless in
writing and signed by duly authorized officers of the parties hereto.
C. This Agreement may not be assigned by the Library to any other person, firm or
corporation without the express written consent of the Association. This
Agreement may not be assigned by Association to any other person, firm or
corporation without the express written consent of the Library and Association
provided however that Association may freely engage subcontractors to perform
its obligations under this Agreement.
D. The Association and the Library agree to use their best efforts and cooperate in
the performance of this Agreement so that its purposes may be successfully
carried out, and to engage in good-faith discussions in the event either party is
dissatisfied with the performance, conduct or actions of the other.
12. INCORPORATION BY REFERENCE
Exhibit A which is attached hereto, is hereby expressly incorporated herein by
this reference.
IN WITNESS WHEREOF, the parties hereto have caused this Agreement to be executed
as of the dates set forth below:
ORANGE COUNTY PUBLIC LIBRARY
By:
Name:
Its:
Date:
4
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
AMERICAN LIBRARY ASSOCIATION, an Illinois not-for-profit corporation
By:
Name: Tracie D. Hall
Its: Executive Director
Date:
By:
Name: Mary Davis Fournier
Its: Executive Director, Public Library Association
Date:
5
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
PUBLIC LIBRARY ASSOCIATION
DigitalLearn.org Library Interface Development
EXHIBIT A-Deliverables
The American Library Association,acting by and through its Public Library Association Division
("Association")owns and manages a product entitled DigitalLearn.org. DigitalLearn.org is an online
resource which builds upon and fosters the work of libraries and community organizations as they work
collaboratively to increase digital literacy across the nation. Included in DigitalLearn.org is a collection of
self-directed tutorials for end-users to increase their digital literacy, and a community of practice for
digital literacy trainers to share resources,tools and best practices.
GOAL
The goal is the development of a customized software interface that will support the Library's
efforts to assist community members with digital skill attainment. The work products resulting from the
performance of this Agreement by Association will include robust tools,features,content and
functionality as set forth below.
ASSOCIATION SERVICES
Association will provide the following services and deliverables to the Library for its use and
hereby acknowledges that it shall:
(1) Interact with,manage, and pay qualified vendors to accomplish software development,
instructional design and other services, as needed,to complete the work described herein.
Association will use the services of CKD Technology Partners. or such other vendor as
Association chooses for product ownership services,web site support and maintenance,and
instructional design services;
(2) Facilitate communication between and among Library representatives,Association and
vendors in order to develop and refine proposed enhancements to the open source software
and interface module,as well as populate specific content(such as registration fields,needs
assessment questions,etc.);
(3) Oversee development,testing(in collaboration with Library representatives),and launch of
the following features and enhancements for Library:
(a) Development of capability for learners across Library to:
i) login to the site and manage personal accounts;
ii) track progress with classes(completions,class progress, etc.)through a learning
plan page;
iii) access PDFs of certificates for assessments they have completed;
iv) access post course content that provides direction and next steps with links and other
customizable resources;
v) a page that provides direction and next steps for different types of learners with
links and other customizable resources
vi) take assessments that are task based in order to receive completion certificates;
vii) add and remove classes from learners'class progress pages (learning plans);
viii) receive class recommendations through a self-directed set of questions;
ix) associate with an organization when registering for the site
(b) Development of an administrative infrastructure to allow the Library to:
6
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
i) track site and class usage at the aggregate and completion level; and
ii) add new class content and make it accessible in the dedicated Library
(4) Provide technical support and expertise in order to improve site functionality and usability in
addition to keeping technology current. This includes maintaining site and software updates
for security,providing incremental support and improvements for increased usability and
ongoing support functionality, and rolling out new site functionality and features periodically;
and
(5) Support hosting and maintenance for the customized software interface following the launch
of the site through November 1, 2022 after which date Association and Library must enter
into a separate agreement for hosting and maintenance.
LIBRARY PARTICIPATION
Library will cooperate with Association as reasonably requested to facilitate the delivery of the
Services and hereby acknowledges that it shall:
(1) Establish an internal development team, including no less than one primary point of contact
and ideally 3-4 additional Library staff,to interact with Association and vendors to complete
the work described herein;
(2) Agree with and adhere to a project timeline developed with the Association and vendors,to
initiate and complete development of the customized software interface over a period of 4-6
weeks;
(3) Provide all materials(logos, color palettes,user registration field, analytic needs)and services
(site review and testing, feedback)required from the Library to create the customized
software interface and adhere to the project timeline;
(4) Identify and support key staff to serve as administrators of the new customized software
interface and ensure those staff have sufficient training to manage the site on an ongoing
basis independent of Association and vendors; and
(5) Post and maintain on the site a privacy policy, licensing information and attributions of credit
for development of the content approved by the Association and make updates to such
information upon request by the Association.
7
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Attachment B-DigitalLearn-Cloud Questionnaire
9�gnge = °4�r� Cloud Service Questionnaire
This questionnaire is to be used to assess security and legal issues
52 surrounding cloud services under consideration for Orange County. For this
questionnaire, cloud services are any services requiring storage of County
11) Cata data outside the County network or provision of computing resources outside
of the County network.
Vendor under consideration:American Library Association
Solution under consideration: DigitalLearn.org
Department(s) served: Library
1. Who owns the data created by County personnel using this service?
American Library Association nor Jende Solutions retains ownership to any data created
by County personnel. Orange county retains ownership of what it creates.
2. Does the Cloud contractually allow the County to access and retrieve its data at the
County's discretion?
Yes, data including course content and usage statistics is available 24/7 to designated
County administrators.
If No, Explain: Click here to enter text.
3. Is the Cloud provider contractually obligated to dispose, return or retrieve data in the
event of contract termination?
Yes: no data is retained on vendor's servers in the event of contract termination.Any
course content that County wishes to retain can be retrieved from the platform prior to
de-provisioning.
If No, Explain: Click here to enter text.
4. Upon such provision of data, is the Cloud provider obligated to specify data format and
all information necessary for data extraction?
N/A- the only data retained on our servers is County course content and the IP address of
end-users who accessed that content while the platform was in use.
If No, Explain: Click here to enter text.
5. Is the Cloud provider obligated to destroy all copies of County data, at the County's
request?
No County data is retained on vendor's servers in the event of contract termination.Any
course content that County wishes to retain can be retrieved from the platform prior to
de-provisioning.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
If No, Explain: Click here to enter text.
6. What are the Cloud provider's obligation to the County in the event of confirmed or
suspected data breaches?
N/A: There is no private or confidential County data stored on vendor's servers. In the
event of data breach, the only data that can be accessed is data County has already
deemed to make public (its generated course content).
7. Is the Cloud provider obligated to inform the County of all locations in which the data is
stored(including backups) and to continually keep the County informed of any changes
to those locations?
N/A: There is no private or confidential County data stored on vendor's servers.
If No, Explain: Click here to enter text.
8. What are the Cloud provider's contractual obligations with respect to litigation holds on
County data?
N/A: There is no private or confidential County data stored on vendor's servers.
9. What are the Cloud provider's contractual prohibitions on disclosing data to individuals,
groups or organizations making record requests, unless so directed by an authorized
County official?
N/A: There is no private or confidential County data stored on vendor's servers.
10. Does the contract obligate the Cloud provider to allow third-party audits and/or
certifications related to infrastructure and security, including penetration testing and
vulnerability assessment, as requested by the County?
Such services are available upon request from County, and at County's expense. Note
there is no private or confidential County data stored on vendor's servers.
If No, Explain: Click here to enter text.
11. Does the contract obligate the Cloud provider to allow third party onsite inspections of
the Cloud provider's infrastructure and security practices on a specified basis?
No: There is no private or confidential County data stored on vendor's servers.
If No, Explain: Click here to enter text.
12. Does the contract obligate the Cloud provider to provide security documentation upon
request by the County?
Yes. Note there is no private or confidential County data stored on vendor's servers.
If No, Explain: Click here to enter text.
13. Does the contract obligate the Cloud provider to supply the County with the provider's
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
performance records, including access to daily and weekly service quality statistics?
No, service records are not available at this time. Note there is no private or confidential
County data stored on vendor's servers.
If No, Explain: Click here to enter text.
14. Explain the contractually obligated service level parameters, minimum levels, specific
remedies and penalties for non-compliance for:
1) Uptime See below
2) Performance and response time: See below
3) Error correction time: See below
4) infrastructure and security: See below
PRIORITY DESCRIPTION TIMING
1 Loss of service,or serious impairment of service,which cannot Upon receiving the Support Request, contact the
be circumvented.Examples of this type of problem are: Client's primary contact to acknowledge the
• Critical product feature does not work(identifiable part of problem report within 60 minutes during the support
functionality),no workaround exists,or workarounds are hours.
unpractical. Verify the problem and notify the Client's primary
Client data is corrupted as a result of a Jende provided contact with the plan of action,within 2 hours.
product or feature. Provide updates at least once every 4 hours or at a
frequency mutually agreed by Client and Jende until
the issue is resolved.
2 A problem exists which can be reason ably_eircumvented by Upon receiving the Support Request, contact the
Client or does not materially affect normal operations. Client's primary contact to acknowledge the
Examples of this type of problem are: problem report within 4 hours.
• A non-functioning product feature which is not critical to Verify the problem and notify the Client's primary
a User(identifiable part of functionality). contact with the plan of action within 8 hours.
• Part of a product feature is affected,a viable workaround Provide updates at least once every 8 hours or at a
exists. frequency mutually agreed by the Client and Jende.
• Highly visible usability problem that doesn't affect
functionality.
3 Any other issue that does not have any effect on normal Upon receiving report of the problem, verify the
operations. problem and notify the Client's primary contact with
an acknowledgement and plan of action within 48
hours.
• Provide updates at least once every 5 business days
or at a frequency mutually agreed by the Client and
Jende.
15. Does the contractually defined Service Level Agreement define pertinent terms such as
downtime, scheduled downtime, etc...?
Yes.
If No, Explain: Click here to enter text.
16. Does the contract specify minimum disaster recovery and business continuity
requirements, including penalties for non-compliance, as discovered through onsite
inspections, audits or actual disasters?
N/A
If No, Explain: Click here to enter text.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
17. Does the contract require the cloud vendor to notify the County of any outsourced
functionality and its provider?
N/A
If No, Explain: Click here to enter text.
1 S. What are the contractually required notification period for the County or the cloud vendor
for termination of the cloud services?
30 Days Notice
19. Describe how the County's data will be stored, managed and archived.
N/A There is no private or confidential County data stored on vendor's servers.
20. Will the County's data be stored and managed on a storage system with other data?
N/A There is no private or confidential County data stored on vendor's servers.
If Yes, Explain: Click here to enter text.
21. At what architectural point in the provider's cloud facility will the County's data be
physically connected to networking equipment with non-County data?
N/A There is no private or confidential County data stored on vendor's servers.
22. What are the cloud provider's information security policies?
Jende Solutions operations, systems and the industry are constantly changing. New threats are routinely
introduced to our environment through systems and operations changes as well as periodic changes in
our staff. To enforce existing security program criteria as well as identify new threats, Jende Solutions
must routinely measure the effectiveness and compliance of its information security program.
Policy Statement
Jende Solutions will monitor, measure, and evaluate the effectiveness, adequacy, and compliance with its
information security program and make adjustments to the program as needed to adequately manage
data security risks. This is accomplished by actively performing ongoing system security reviews.
Reviews will be performed by Information Technology department staff, the Chief Information Security
Officer (CISO), Jende Solutions Internal Audit, and Jende Solutions's auditors or regulators. Summary
reports of the effectiveness, adequacy, and compliance will be made periodically to the Security/IT
Steering Committee, Jende Solutions Executive Leadership Team, and the Board of Directors. The
reports will also discuss changes and additions to the company's information security program deemed
advisable to properly protect information assets.
Applicability
This policy will be enforced by company management and the Security/IT Steering Committee. The scope
of audits will impact all managers regarding staff training, risk management and effectiveness of security
controls.
Standards
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
The CISO is responsible for establishing a monitoring and reporting program that contains the following:
• Security Monitoring
• Internal Testing
• External Examination
Risk Management Reviews
The Security/IT Steering Committee and Board of Directors of Jende Solutions continuously strive to
maintain a clear understanding of the types of information security risks to which Jende Solutions is
exposed. This is accomplished by:
• Delineating clear accountability and lines of authority across Jende Solutions's businesses and
information security activities.
• Conducting an annual review of threats and hazards to critical operations and adjusting the
information security program accordingly.
• Maintaining an active oversight role as products, services, and new technologies are instituted
and improved.
• Providing clear guidance regarding acceptable levels of security over Jende Solutions's
information assets.
• Ensuring that the established policies, procedures, and controls are communicated to and
observed by all employees.
• Annually reviewing and approving information systems and security policies to ensure that the
policies address security risks, are aligned with Jende Solutions's overall business and
technology strategies, and comply with relevant laws, regulations, and rulings.
• Performing an annual review and approval of the internal audit program for scope and frequency
concerning compliance with information security policies.
Security Monitoring
The CISO is responsible for coordinating the monitoring program for all information systems activities and
reporting any significant violations to company policy to Senior Management and the Security/IT Steering
Committee. This includes oversight of the following duties:
IT Department Responsibilities
• Perform a periodic review of all systems management logs, system/application activity reports,
and disk usage to search for possible security incidents. If a possible intrusion is identified,
implement procedures as outlined in the Incident Response Policy.
• Perform all scheduled maintenance to include software updates and maintain a log of services
performed.
• Perform an annual audit of all systems, software and peripheral devices to ensure an accurate
software and hardware inventory.
• Immediately remove any unlicensed software, hardware, or unauthorized modems from the
network or any system.
• Periodically review and clear error logs.
• Review media backup and anti-virus logs daily to ensure that no viruses are detected and that the
data was successfully backed up the previous night.
• Periodically review user and group security profiles. This includes reviewing user access to
systems and data based upon their business responsibilities, granting access rights based upon
these job functions, and ensuring security profiles are promptly modified or revoked upon a
change in job function or termination. For each audit entry, the following information will be
recorded:
■ Date and Time of event
■ User ID and User involved in the event
■ Type of User action
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
• At least once per month, review system access logs and remove any terminated users from the
access control lists. Validate termination lists with Human Resources or the user's supervisor
before removal.
• Ensure vulnerabilities are managed according to the standards of the Network and Systems
Operations Policy.
• Logging must be enabled at the operating system, application\database and system level. All logs
must be sent to their designated central log system. 90 days of logs will be stored in an online
storage in SIEM (Security Information and Event Management) system. At least one year of logs
will be maintained at all times, either online or offline, easily accessible in the event of an incident
for review.
• Ensure that internal and external network vulnerability scans are run at least quarterly and after
any significant change in the network (e.g., new system component installations, changes in
network topology, firewall rule modifications, product upgrades).
• Internal and external vulnerability scans with vulnerabilities will be sent to appropriate teams to
address. Rescans will be performed once remediation work has been completed. This will
continue until a passing results are obtained.
• Conduct periodic "spot checks" of system configurations to ensure standard systems
configuration guidelines are being followed.
• Ensure that penetration tests are conducted according to the standards of the Network and
Systems Operations Policy.
• Ensure that a wireless analyzer is used periodically to identify all wireless devices in use.
• Ensure that all alerts from file integrity monitors and intrusion detection systems are promptly
reviewed.
• Test security controls, limitations, network connections and restrictions routinely to make sure
they can adequately identify or stop any unauthorized access attempts
Internal Audit Testing Methodology
• The designated Jende Solutions internal auditor will perform an annual audit of Information
Technology (IT) systems. The audit will include testing risk management and operational
processes and render a report to the Audit Committee of the Board of Directors regarding the
information security program and overall information systems activities and related operations.
The auditor and the Chief Information Security Officer (CISO) will track all exceptions. The CISO
will prepare a response for any deficiencies identified in the audit report.
• The auditor is charged with responsibility for an annual in-depth review of all network and
information systems activities, related controls, training support, supporting operations and
related policies and procedures, internal reporting systems, and Management's follow-up on
previously cited exceptions. Audit reports will be issued to the Executive Leadership Team, the
Security/IT Steering Committee, and the Jende Solutions Board of Directors.
• This will include internal vulnerability assessment and web application scans being performed at
least quarterly and after any significant changes in the network or applications respectively.
External Vulnerability Assessment and Penetration Testing
• The CISO will supervise an independent assessment for the effectiveness of the Jende Solutions
information security program at least once per year. At a minimum, the assessment should
include evaluating systems security parameters and profiles such as access controls, password
strength, network privileges, system configuration, vulnerability management, security safeguard
implementation, staff training, startup files, and login violations. The CISO is also responsible for
ensuring penetration tests are performed at least annually and after significant infrastructure
changes, application upgrades or modification.
• The CISO will also coordinate all required external vulnerability scans to ensure compliance with
Jende Solutions Policies. The CISO is responsible for ensuring that all vulnerabilities detected in
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
the scans are reported to the CTO. The CTO will be responsible for ensuring that all identified
vulnerabilities are remediated to levels acceptable to the Jende Solutions CISO.
• The external assessment will be presented to the Security/IT Steering Committee and Board of
Directors to assist in their understanding of threats and hazards for sensitive information and
systems.
Penetration Testing Methodology
Penetration testing allows for the validation of information obtained from vulnerability and web application
vulnerability scans. The primary focus of penetration testing it to identify legitimate exploits that could
grant an unauthorized user access to the Jende Solutions environment. The groundwork for this test
is/will be based on the methodology of Penetration Testing Execution Standard (PTES —
www.pentest-standard.org) for systems and network and the Web Application Penetration Testing
methodology of OWASP (www.owas.00rg). This is at a high level a four phase process.
1. Phase one— Reconnaissance
a. Information gathering via vulnerability assessment tools, port scans and OS
fingerprinting.
2. Phase two—Target prioritization
a. External—Web or application servers, mail, network, DNS
b. Internal—OS patching, database configuration, password security
3. Phase three— Exploitation
a. Validating that identified threats can be exploited and capturing sufficient evidence as to
allow administrators to effectively implement solutions.
4. Phase four- Re-testing
a. Once remediation has been completed, each successfully exploited item must be
retested to ensure desired results were achieved.
23. What are the cloud provider's incident management and reporting policies?
Information collection, processing, storage and sharing are essential for Jende Solutions to deliver
services to its customers. However, that information is also valuable to those who would misuse that data
to cause damage to Jende Solutions, or defraud its customers. Jende Solutions has deployed
administrative, technical and physical controls to protect sensitive company information as well as
customer privacy. However, if controls to protect sensitive data are somehow compromised, Jende
Solutions must have an Incident Response Plan to mitigate damage, investigate the cause and recover
services. The purpose of this policy is to establish guidelines for the development of Jende Solutions's
response to unauthorized network intrusions or other significant information security incidents.
Policy Statement
Incident Response is the final stage in a process that escalates events through an operation review
process to determine if an event was observed on a production processing system could have caused a
breach of the system or compromise of sensitive data. Jende Solutions will appoint an Incident Response
Team (IRT)and maintain a plan to effectively guide response to an incident.
Scope
All employees must report all suspicious actions, activities and incidents to the IT department using the
Incident reporting form.
Standards
Jende Solutions will prepare and maintain an incident response plan that will enable the Incident
Response Team to respond immediately to a system breach or compromise.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
The plan will address specific incident response procedures, business recovery and continuity
procedures, data backup processes, roles and responsibilities, and communication and contact strategies
(e.g., informing HHS and State/Local authorities).
The intent of the Incident Response Plan is to mitigate risk, and the company will respond to incidents
according to the following priorities:
• Human life and safety.
• Sensitive or mission-critical systems and data.
• Other systems and data.
• Damage to systems and data.
• Disruption to access or services. Specifically, this Incident Response Plan (IRP) is designed to:
• Reduce potential direct and indirect financial loss from network intrusions.
• Mitigate operational impact from cyber incidents.
• Comply with regulatory requirements for information security.
• Identify and respond to rogue devices (including wireless access devices)on networks.
• Meet industry best practices as published by the FBI and National Infrastructure Protection
Center(NIPC).
Jende Solutions characterizes cyber incidents as any unwanted, or in some instances, unexplained
network or system behavior. Jende Solutions segments these incidents into the following categories
consistent with definitions published by the National Infrastructure Protection Center(NIPC):
• Increased access to information assets
• Unauthorized disclosure of information
• Corruption of information
• Denial of Service
• Theft of IT resources
The plan will include:
• Roles, responsibilities, and communication strategies in the event of a compromise to include
designation of an Incident Response Team (IRT).
• Coverage and responses for all critical system components.
• Establish a formal process to report incidents and track response activities
• Guide response in the following phases:
• Preparation
• Identification
• Containment
• Eradication
• Recovery
• Follow-up/ Lessons Learned
• Define escalation processes.
• Procedures to conduct a post event review to determine the cause and guide control
enhancements.
• Procedures for notification, at a minimum, of covered entity and if applicable HHS/OCR.
• A strategy for business continuity post compromise.
• Reference or inclusion of incident response procedures from the covered entity and if applicable
HHS/OCR.
• An analysis of legal requirements for reporting compromises as required by State Privacy laws
Jende Solutions will ensure:
• Integrate event escalation procedures to identify incidents that require declaration of an incident.
• Notice will be provided to proper authorities if sensitive data is compromised (See Appendix A for
contact numbers).
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
• 24/7 incident response and monitoring coverage for any evidence of unauthorized activity, critical
IDS alerts, and/or reports of unauthorized critical system or content file changes.
• Specific personnel are designated to be available on a 24/7 basis to respond to compromise
alerts.
• Provide appropriate training to staff with security breach response responsibilities as is industry
standard best practices.
• Establish a process to modify and evolve the incident response plan according to lessons learned
and to incorporate industry developments.
At a minimum, Jende Solutions will conduct a test of the Incident Response plan and the ability of the
incident response team to execute the plan on an annual basis. A copy of the test plan and test results
will be maintained for a period of at least one year. Any gaps in the security plan or staff training will be
identified in the plan testing and reported to the Security/IT Steering Committee for plan modification and
incorporation of lessons learned.
24. What is the process by which the cloud provider updates policies and informs customers?
N/A
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
25. What is the basic architecture of the cloud provider's network security? (overall design,
zones, filters, firewalls, VLANs,protocols, standards)
AWS Account
vpc
Prlvete Subnet — Private Su6ne1
Amnon
..+
EKS
Custoers Ffetworks M
Aws nos
,p
m PG BUJ 1930i
AWS WAF 8 Amazon EC2
Kubernetes
r� Worker Xdes
User Devices
Amnion
ElaBtiCn[nB 101
neela
A.—
AmO 33
clauewacca
26. What security measures does the cloud provider use in data storage, transit and use?
• Secure (encrypted) transmission of data to external entities or within the company, which
involves the following aspects.
• Jende Solutions will use strong cryptography and encryption techniques (at least 256 bit)
such as Transport Layer Security (TLS) TLS 1.1 or higher, Point-to-Point Tunneling
Protocol (PPTP), and Internet Protocol Security (IPSEC) to safeguard confidential data
during transmission over public networks.
• Confidential information must be encrypted for transmission over wireless networks. The
transmissions will be encrypted by using Wi-Fi Protected Access (WPA2) technology if
WPA2 capable, and/or VPN or SSL at least 256.
• Email encryption software licensed by Jende Solutions will be deployed on personal
computers/laptops used by employees. Confidential data must not be sent in
unencrypted email.
• Jende Solutions will implement encryption for data at rest to ensure that confidential data
is unreadable anywhere it is stored, (including data on portable media, in logs, and data
received from or stored by wireless networks) by using any of:
■ One-way hash
■ Truncation
■ Index tokens and PADs, with the PADs being securely stored
■ Strong cryptography, such as AES 256-bit
• Cryptographic strength must not be less than 256-bits, using industry acceptable
encryption or hashing algorithms.
• Establish clear procedures and responsibilities for key management; including key
rotation, key storage, key selection, and key handling.
• Ensure the secure storage and exchange of all access control passwords.
• Encryption tokens will be used to deploy"administrator" dual factor authentication, where
required.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
• All non-console administrative access will be encrypted using technologies such as SSH,
VPN, or TLS 1.1 or newer for web-based management and other non-console
administrative access.
27. What encryption technologies does the cloud provider use in data management?
See answer to question#26
28. How are access rights managed by the cloud provider for their employees, contractors
and other persons?
Jende Solutions recognizes that our personnel are the greatest resource in maintaining an effective level
of security. At the same time, internal threats can create the greatest risks to information security. No
security program can be effective without maintaining security awareness for employees, relevant
contractors, and relevant third party users. Relevant contractors and relevant third party users are defined
as those personnel with administrative access and/or access to sensitive data/information based on job
function, or by accessing Jende Solutions information systems without employee oversight.
Every Jende Solutions employee, contractor, third party user, service provider, or vendor is responsible
for systems security to the degree that the function requires the use of information and associated
systems. Fulfillment of security responsibilities is mandatory and violations of security requirements may
be cause for disciplinary action, up to and including dismissal, civil penalties, and criminal penalties.
All positions interacting with Jende Solutions information resources must be required to undergo formal
processes for access granting, change, and termination. Those positions working with especially sensitive
information or powerful privilege must be analyzed to determine any potential vulnerability associated with
work in those positions, prior to assignment of these roles.
Applicability
Jende Solutions Human Resources Department (HR) in conjunction with Management will establish staff
guidelines and all staff, relevant contractors and relevant third party users will comply with those
guidelines.
Standards
The Human Resource Department will support the Chief Information Security Officer(CISO)to implement
the following personnel security safeguards:
• Hiring Practices
• Security awareness education and training
• Termination Practices
Hiring Practices
Each new hire granted access to client information and other classified Jende Solutions data will undergo
a background check. Any past activity that would subject sensitive systems and data to risk due to an
employee's past behavior will be cause to terminate the employment relationship with Jende Solutions.
Prior to granting access to classified systems and data, all new hires will receive orientation and training
that include responsibilities for protecting classified information. As outlined in the Access Control Policy,
a new employees' supervisor must approve access to systems on a "business need-to-know" basis and
submit the Systems Access Request Form to both IT and HR for processing.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
The new employee must sign a Statement of Understanding and the Systems Access Request Form
acknowledging acceptance of responsibilities contained in the Jende Solutions security policies. These
policies will be provided to the employee candidate during orientation.
The IT Department will enable access to only those systems approved on the Access Request Form and
will retain a copy of the completed form for auditing. Access may only be granted once a signed
Statement of Understanding has been received by Human Resources.
All new hires must execute a Confidentiality Agreement to protect Jende Solutions sensitive and
confidential information, including any client sensitive information.
Relevant contractors, relevant third party users, and temporary employees will be held to the same
standard as full time employees. A written guarantee from the contractor's organization or the
employment agency that a background check has been conducted with respect to relevant contractors
and relevant third party users can be used to augment internal background checks. Any vendor that
requires access to confidential data regulated by the HIPAA must contractually acknowledge their
responsibilities in maintaining regulatory compliance requirements. This requirement is fully described in
the Jende Solutions Vendor Management Policy.
Training
Department managers, at the direction of Human Resources, are responsible for providing security
orientation and ongoing instruction to new and existing end-users regarding their department's utilization
of Jende Solutions information systems. IT is responsible for informing end-users of pending operational
changes affecting technology and to assist them once the changes are in place.
New Hire Orientation
Each new-hire will complete orientation training to include an overview of Jende Solutions security
policies and procedures. The security policies will include end user acceptable use as well as data
handling and disposal training in addition to other security safeguards. Moreover, these employees will
receive network training as well as training for the use of the systems and applications required to perform
their job functions.
In-House Instruction
All staff, relevant contractors and third party users will be trained on security, compliance, and operating
procedures to effectively use Jende Solutions information systems and applications required while
performing their duties. In addition, all staff will be given periodic security awareness training including but
not limited to a review of relevant Jende Solutions policies and procedures, technology changes, business
controls, legal requirements, appropriate use of information processing facilities, reporting information
security incidents, the importance of protecting customer customer PII, PHI and other sensitive data types
and their handling), and information regarding the disciplinary process for non-compliance with security
policies and procedures. This training is performed as new systems or enhancements are introduced or
may be annually performed in order to ensure that the staff is following the established policies,
procedures and guidelines.
The Chief Information Security Officer will periodically perform security and compliance presentations with
Senior Management to ensure that they have an understanding of the IT processes and related security
control concepts and regulatory requirements.
Security Reminders
The Chief Information Security Officer will continue security education using sign-in banners, posters,
memos, promotions, letters or emails and periodic meetings to re-enforce security training concepts. The
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Information Technology Steering Committee, in conjunction with the Chief Information Security Officer, will
assess the adequacy of the security awareness education and training program on a yearly basis.
Termination Processes
The following standards will be followed upon the resignation of an employee, member of Management,
IT Staff contractor or third party user, or service provider.
Employee Resignation
• Human Resources will immediately notify IT when the resignation is received.
• The Supervisor and/or Management Team will determine if access privileges will be continued for
the notice period, adjusted or immediately terminated. IT will implement procedures as directed
by the Supervisor.
• A monthly report will be forwarded to the Chief Information Security Officer by Human Resources
that lists all terminations during the month and confirmation that all building access and system
access privileges have been terminated.
Employee Termination
• Human Resources will notify IT immediately upon termination of an employee.
• IT will implement procedures as directed by the supervisor to immediately terminate all facility
and system access rights.
Management Resignation
• Human Resources will immediately notify the Chief Information Security Officer when
management resignation is received.
• Administrative rights to the network will be immediately revoked. User rights will be maintained.
• Any server passwords known by the management employee will be immediately changed.
• Continued offsite access, as well as the usage of any portable equipment assigned (hardware,
software and other materials), will be determined as agreed upon by the remaining executive
management team.
IT Staff Resignation or Termination
• A determination must be made by management as to whether to allow the employee to work
during the notice period or to have them leave immediately.
• Each of the above procedures for management resignation must be followed.
Third Parties (to include temporary workers and contractors)
• All hardware, e.g. laptops, security fobs, network hot-spots, will be returned to Jende Solutions on
the last day of the person's employment.
• All network access will be revoked on the representative's last working day.
• All residual vendor or partner management and reporting will be accomplished through the use of
hard copy materials or through supervised access to limited information.
• All customer information or other confidential Jende Solutions information will be returned to
Jende Solutions upon termination of contract.
29. What methods does the cloud provider use to destroy information, when so authorized?
Database record removal, log record removal, backup removal of the preceding list.
30. What is the cloud provider's patch management policy/methods?
Patching occurs monthly, or earlier depending on security alerts and critical
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
vulnerabilities /threats
31. How does the cloud provider defend against malware, including but not limited to
viruses, bots, spyware, spam, phishing and pharming?
Jende Solutions will deploy network perimeter controls to regulate traffic moving between trusted internal
resources and external, untrusted entities. Jende Solutions's virtual network security controls
implementation must protect against known and unknown threats through a combination of a thorough
understanding of information risks, best-practice security configurations, and an alignment with Jende
Solutions's business requirements.
Applicability
This policy applies to all the IT staff responsible for managing, implementing, and administering the
security of the Jende Solutions networks.
Standards
Virtual Network administrators will maintain a configuration management program for network devices
that identify all key aspects of the program and its management. At a minimum, the program must
encompass network controls and routers, and include exact documentation of:
• The current network topography (in diagram form, representing logical and physical composition)
that includes all connections to and from confidential networks.
• A list of all ports and services used for business connections to and from segments carrying
confidential data.
• Business justification for all insecure ports in use between confidential networks and
public/untrusted networks (e.g., FTP, Telnet, etc).
• Roles and responsibilities for device management.
• The formal process for requesting and implementing changes to network control configuration.
The Chief Information Security Officer will conduct periodic reviews of the network control configuration
changes to ensure compliance to documented standards and completeness of documentation. Exact
standards to be deployed on network devices must adhere to the following:
Perimeter Security - Jende Solutions will deploy and maintain perimeter security protection that
include:
Network Segmentation
• All Internet facing applications will be deployed in a Demilitarized Zone (DMZ). All VPN and other
secure connections to partners and clients will be routed through the Jende Solutions network
controls to establish monitoring and logging controls. Outbound DNS queries from a central DNS
service are not required to originate within the DMZ.
• All user LAN segments will be separated from production servers through the use of a firewall or
an Access Control List (ACL)on the local switch/router.
• All servers storing, processing, or transmitting confidential data must be segmented away from
both non-confidential servers and user segments by the use of internal routers or firewalls.
Virtual Network Controls
• Jende Solutions will only use network controls capable of conducting stateful packet inspection.
All network controls used to technically support the network control configuration program must
have this feature as part of its core technical specification.
• Active network controls configurations must comply with the network control configuration
program approved by the CISO and maintained in the IT Procedures Guide. Tools will be
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
deployed to alert security personnel if the "running" configuration of any device does not align to
the approved "stored" configuration.
• All external network connections rules must be approved by the Chief Information Security
Officer, and submitted to the Security/IT Steering Committee for review. Changes to the network
control ruleset may not be implemented until written approval from the Chief Information Security
Officer is obtained.
• Network administrators are responsible for maintaining a set of logical and physical network
diagrams that fully document all connections to PHI and PII data, including any wireless
networks.
• Network controls must be installed at each Internet connection and between any DMZ and the
Intranet.
• The network controls must restrict connections between publicly accessible servers and any
system component storing sensitive(I.e. PHI, PII) data, including any connections from wireless
networks. As part of the firewall configuration program, all connections between the DMZ and
internal networks must be fully documented.
• The DMZ must be considered a semi-public network. As such, all connections carrying
confidential data within the DMZ (including those originating from trusted, internal networks) must
be encrypted.
• The network controls must restrict inbound Internet traffic to IP addresses within the DMZ. No
direct connections between the Internet and the internal virtual network is allowed.
• The network controls must be configured so that RFC 1918 cannot pass from the Internet into the
DMZ\externally. Additionally, dynamic packet filtering will be performed to ensure that only
established connections are allowed into the network.
• Databases with sensitive information will be placed in an internal network zone, segregated from
the DMZ.All inbound and outbound Internet traffic will be monitored.
• All Internet traffic passing into the DMZ will be limited to ports included in documented business
justification that has been approved by the Chief Information Security Officer.
• Jende Solutions considers all wireless networks to be public networks. As such, perimeter
network controls must be installed between any wireless networks and the internal network. The
configuration of these network controls will be set up to deny or control (if such traffic is
necessary for business purposes) any traffic from the wireless environment.
• Personal firewall software must be installed on any mobile and/or employee-owned computers
with direct connectivity to the Internet (e.g., laptops used by employees), which are used to
access the Jende Solutions's network.
• The network controls must use network address translation (NAT) to mask internal addresses
from the Internet.
• Direct connections are not allowed between the Internet and the sensitive data (i.e. PII/PHI)
environment.
• Disclosure of internal IP addressing and routing information to unauthorized third parties is not
permitted.
• The network controls must limit inbound and outbound traffic to specifically what is necessary for
the sensitive data (i.e. PII/PHI)environment and be reviewed on a semi-annually basis.
• Network control rules and router access lists will be reviewed and approved every six (6) months
by the CISO.
32. What system hardening strategies are employed by the cloud provider?
See answer to question#31
33. How does the cloud provider perform security testing, including logging, correlation,
intrusion detection, intrusion prevention, file integrity monitoring, time synchronization,
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
security assessments,penetration testing?
See answer to question#31
34. What technologies and methods does the cloud vendor provide for strong authentication?
Minimum password length, administratively controlled user access
35. Provide any other comments and explanations:
Click here to enter text.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Attachment C-DigitalLearn-Cyber Liability Questionnaire_Digital Learning Cyber Policy
01"S% :F ��`�� Cyber Liability Insurance Questionnaire
01' �b
This questionnaire is to be used to assess the level of Cyber Liability
it 5� Insurance procured by the vendor under consideration for Orange County.
°r16 Ca%'D �4
Vendor under consideration:American Library Association
Solution under consideration: DigitalLearn.org
Department(s) served: Library
1. Do you currently have Cyber Liability Insurance?
Yes
a. If yes, what coverage is provided by your insurance policy?
COVERAGE SCHEDULE(Currency in USID)
Limit Retention
Each Claim Limit of Liability:
Media, Tech,Data&Network Liability: $3,000,000
Policy Aggregate Lim It of Liability: $3,000,000
Additional Defense Limit: Not Included
Media,Tech,Data&Network Liability
Tech&Professional Services: $3,000,000 each Claim$5,000
Tech Product: $3,000,000 each Claim$5,000
Media: $3,000,000 each Claim$5,000
Data&Network: $3,000,000 each Claim$5,000
Breach Response
Breach Response Costs: $3,000,00D each incident$0
Regulatory Defense&Penalties
Regulatory Defense&Penalties: $3,000,000 each Claim$5,000
Payment Card Liabilities&Costs
Payment Card Liabilities&Costs: $3,000,000 each Claim$5,000
First Party Data&Network Loss
Business Interruption Lass:
Resulting from Security Breach: $3,000,00D each incident$5,000
Resulting from System Failure: $3,000,000 each incident$5,000
Dependent Business Loss:
Resulting from Dependent Security Breach: $250,000 each incident$5,000
Resulting from Dependent System Failure: $250,000 each incident$5,000
Cyber Extortion Loss: $3,000,000 each incident$1,000
Data Recovery Costs: $3,000,ODD each incident$5,000
eCrime
Fraudulent Instruction: $250,000 each loss$5,000
Funds Transfer Fraud: $250,000 each loss$5,000
Telephone Fraud: $250,000 each loss$5,000
Criminal Reward
Criminal Reward: $50,000
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
b. Provide a copy of the insurance.
See Attached.
2. If your answer to question 1 was No, then are you planning to get Cyber Liability
Insurance?
a. If Yes, When do you plan to get it:
b. If No, Explain why not:
3. Provide any other comments and explanations:
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Beazley MediaTech
THIS POLICY'S LIABILITY INSURING AGREEMENTS PROVIDE COVERAGE ON A CLAIMS MADE
AND REPORTED BASIS AND APPLY ONLY TO CLAIMS FIRST MADE AGAINST THE INSURED
DURING THE POLICY PERIOD OR THE OPTIONAL EXTENSION PERIOD (IF APPLICABLE) AND
REPORTED TO THE UNDERWRITERS IN ACCORDANCE WITH THE TERMS OF THIS POLICY.
AMOUNTS INCURRED AS CLAIMS EXPENSES UNDER THIS POLICY WILL REDUCE AND MAY
EXHAUST THE LIMIT OF LIABILITY AND ARE SUBJECT TO RETENTIONS.
These Declarations along with the statements contained in the information and materials provided to
the Underwriters in connection with the underwriting and issuance of this Policy, and the Policy with
endorsements shall constitute the contract between the Insureds and the Underwriters.
GENERAL INFORMATION
Insurer/Underwriter: Beazley Insurance Company, Inc. (Admitted)
Named Insured: Jende Solutions Inc
Named Insured Address: 301 University Boulevard
Galveston, TX 77555
Notice of Claim, Loss or Beazley Group
Circumstance: Attn: Cyber& Tech Claims Group
45 Rockefeller Plaza, 16th floor
New York, NY 10111
cyber&techclaims@beazley.com
Administrative Notice: Beazley USA Services, Inc.
30 Batterson Park Road
Farmington, CT 06032
Tel: (860) 677-3700
Fax: (860) 679-0247
F00730 1 of 4
022019 ed.
Date Issued:25-May-2021
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
POLICY INFORMATION
Policy Number: VG00003589AB
Policy Form: Beazley MediaTech (F00731 022019 ed.)
Policy Period: From: 03-Jul-2021 To: 03-Jul-2022
Both at 12:01 AM Local Time at the Named Insured Address
Retroactive Date: 05-Feb-2019
Continuity Date: 03-Jul-2020
Optional Extension Period: 12 Months
Optional Extension Premium: 100% of the Annual Policy Premium
Waiting Period: 8 Hours
Premium: $6,864.00
F00730 2 of 4
022019 ed.
Date Issued:25-May-2021
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
COVERAGE SCHEDULE (Currency in USD)
Limit Retention
Each Claim Limit of Liability:
Media, Tech, Data &Network Liability: $3,000,000
Policy Aggregate Limit of Liability: $3,000,000
Additional Defense Limit: Not Included
Media, Tech, Data& Network Liability
Tech & Professional Services: $3,000,000 each Claim$5,000
Tech Product: $3,000,000 each Claim$5,000
Media: $3,000,000 each Claim$5,000
Data& Network: $3,000,000 each Claim$5,000
Breach Response
Breach Response Costs: $3,000,000 each incident$0
Regulatory Defense&Penalties
Regulatory Defense& Penalties: $3,000,000 each Claim$5,000
Payment Card Liabilities&Costs
Payment Card Liabilities&Costs: $3,000,000 each Claim$5,000
First Party Data&Network Loss
Business Interruption Loss:
Resulting from Security Breach: $3,000,000 each incident$5,000
Resulting from System Failure: $3,000,000 each incident$5,000
Dependent Business Loss:
Resulting from Dependent Security Breach: $250,000 each incident$5,000
Resulting from Dependent System Failure: $250,000 each incident$5,000
Cyber Extortion Loss: $3,000,000 each incident$1,000
Data Recovery Costs: $3,000,000 each incident$5,000
eCrime
Fraudulent Instruction: $250,000 each loss$5,000
Funds Transfer Fraud: $250,000 each loss$5,000
Telephone Fraud: $250,000 each loss$5,000
Criminal Reward
Criminal Reward: $50,000
F00730 3 of 4
022019 ed.
Date Issued:25-May-2021
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
ENDORSEMENTS •
1. A01110TX 052020 ed. Important Notice -Texas
2. A01150TX 032014 ed. Notification of the Availability of Loss Control Information/Services -
Texas
3. A01801 TX 092019 ed. Texas Amendatory Endorsement
4. BICMU05090406 Nuclear Exclusion
5. E02804 032011 ed. Sanction Limitation and Exclusion Clause
6. E12254 022019 ed. War and Civil War Exclusion
7. E12287 022019 ed. Asbestos, Pollution and Contamination Exclusion Endorsement
8. E12228 022019 ed. Aggregate/Maintenance Retention
9. E12266 022019 ed. Amend Definition of Fraudulent Instruction
10. E12269 022019 ed. GDPR Cyber Endorsement
11. E12289 022019 ed. Computer Hardware Replacement Cost
12. E12290 022019 ed. Contingent Bodily Injury With Sublimit Endorsement
13. E12293 022019 ed. Invoice Manipulation Coverage
14. E12716 022019 ed. Post Breach Remedial Services Endorsement
15. E12864 042019 ed. Crisis Management Expense Coverage
16. E12972 052019 ed. CryptoJacking Endorsement
17. E13040 062019 ed. Reputation Loss
18. E13373 092019 ed. State Consumer Privacy Statutes Endorsement
19. E13916 052020 ed. Employee Device Endorsement
20. E12300 022019 ed. Voluntary Shutdown Coverage
25-May-2021
Authorized Representative Date
Secretary President
F00730 4 of 4
022019 ed.
Date Issued:25-May-2021
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Beazley MediaTech
TABLE OF CONTENTS
INSURING AGREEMENTS Subsidiary................................................................. 13
System Failure........................................................... 13
Media,Tech, Data&Network Liability..........................1 Tech Products........................................................... 14
Breach Response..........................................................1 Tech&Professional Services Wrongful Act........... 14
Regulatory Defense&Penalties...................................1 Tech Product Wrongful Act...................................... 14
Payment Card Liabilities&Costs.................................1 Tech Services............................................................ 14
First Party Data&Network Loss..................................2 Telephone Fraud....................................................... 14
eCrime............................................................................2 Third Party Information............................................. 14
Criminal Reward............................................................2 Transfer Account...................................................... 14
Unauthorized Access or Use.................................... 14
DEFINITIONS 2 Unauthorized Disclosure.......................................... 14
Waiting Period........................................................... 15
Additional Insured.........................................................2
Breach Notice Law.........................................................3 EXCLUSIONS
Breach Response Costs................................................3
Business Interruption Loss...........................................3 Bodily Injury or Property Damage............................ 15
Claim..............................................................................4 Deceptive Business Practices,Antitrust&
Claims Expenses...........................................................4 Consumer Protection................................................ 15
Computer Systems........................................................4 Distribution of Information....................................... 15
Continuity Date..............................................................5 Prior Known Acts&Prior Noticed Claims............... 15
Control Group................................................................5 Racketeering, Benefit Plans,Employment
Criminal Reward Funds.................................................5 Liability&Discrimination......................................... 16
Cyber Extortion Loss.....................................................5 Sale or Ownership of Securities&Violation of
Damages........................................................................5 Securities Laws......................................................... 16
Data................................................................................6 Criminal,Intentional or Fraudulent Acts................. 16
Data Breach....................................................................6 Patent&Misappropriation of Information............... 16
Data&Network Wrongful Act.......................................6 Governmental Actions.............................................. 17
Data Recovery Costs.....................................................6 Other Insureds&Related Enterprises..................... 17
Dependent Business.....................................................6 Trading Losses&Loss of Money............................ 17
Dependent Business Loss............................................6 Contractual................................................................ 17
Dependent Security Breach..........................................7 Retroactive Date........................................................ 17
Dependent System Failure............................................7 Recall.........................................................................18
Digital Currency.............................................................7 Infrastructure Failure................................................ 18
Extortion Payment.........................................................7 Licensing Bodies&Joint Ventures......................... 18
Extortion Threat.............................................................7 Over-Redemption...................................................... 18
Extra Expense................................................................7 First Party Data&Network Loss ............................. 18
Financial Institution.......................................................7
LIMIT OF LIABILITY AND COVERAGE 19
Forensic Expenses........................................................8
Fraudulent Instruction...................................................8
Funds Transfer Fraud....................................................8 RETENTIONS
Income Loss...................................................................9
Individual Contractor.....................................................9 OPTIONAL EXTENSI• PERIOD 19
Insured...........................................................................9
Insured Organization.....................................................10 GENERAL CONDITIONS
Loss................................................................................10
Media Activities.............................................................10 Notice of Claim or Loss............................................20
Media Material................................................................10 Beazley Breach Response Services........................20
Media Wrongful Act.......................................................10 Notice of Circumstance............................................21
Merchant Services Agreement......................................11 Defense of Claims.....................................................21
Money.............................................................................11 Settlement of Claims.................................................22
Named Insured...............................................................11 Assistance and Cooperation....................................22
PCI Fines Expenses and Costs.....................................11 Subrogation...............................................................23
Penalties.........................................................................11 Other Insurance........................................................23
Period of Restoration....................................................11 Action Against the Underwriters..............................23
Personally Identifiable Information...............................12 Entire Agreement......................................................23
Policy Period..................................................................12 Mergers or Consolidations.......................................23
PrivacyPolicy................................................................12 Assignment...............................................................24
Privacy Policy Violation................................................12 Cancellation..............................................................24
Professional Services....................................................12 Singular Form of a Word..........................................24
RegulatoryProceeding..................................................13 Headings....................................................................24
Retroactive Date............................................................13 Representation by the Insured.................................24
Securities.......................................................................13 Named Insured As Agent..........................................24
SecurityBreach.............................................................13
F00731
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Beazley MediaTech
THIS POLICY'S LIABILITY INSURING AGREEMENTS PROVIDE COVERAGE ON A CLAIMS MADE
AND REPORTED BASIS AND APPLY ONLY TO CLAIMS FIRST MADE AGAINST THE INSURED
DURING THE POLICY PERIOD OR THE OPTIONAL EXTENSION PERIOD (IF APPLICABLE) AND
REPORTED TO THE UNDERWRITERS IN ACCORDANCE WITH THE TERMS OF THIS POLICY.
AMOUNTS INCURRED AS CLAIMS EXPENSES UNDER THIS POLICY WILL REDUCE AND MAY
EXHAUST THE LIMIT OF LIABILITY AND ARE SUBJECT TO RETENTIONS.
Please refer to the Declarations, which show the insuring agreements that the Named Insured
purchased. If an insuring agreement has not been purchased, coverage under that insuring agreement of
this Policy will not apply.
The Underwriters agree with the Named Insured, in consideration of the payment of the premium and
reliance upon the statements contained in the information and materials provided to the Underwriters in
connection with the underwriting and issuance of this Insurance Policy (hereinafter referred to as the
"Policy") and subject to all the provisions, terms and conditions of this Policy:
INSURING AGREEMENTS
Media, Tech, Data & Network Liability
To pay Damages and Claims Expenses, which the Insured is legally obligated to pay
because of any Claim first made against any Insured during the Policy Period for a:
1. Tech & Professional Services Wrongful Act;
2. Tech Product Wrongful Act;
3. Media Wrongful Act; or
4. Data & Network Wrongful Act.
Breach Response
To indemnify the Insured Organization for Breach Response Costs incurred by the
Insured Organization because of an actual or reasonably suspected Data Breach or
Security Breach that the Insured first discovers during the Policy Period.
Regulatory Defense & Penalties
To pay Penalties and Claims Expenses, which the Insured is legally obligated to pay
because of a Regulatory Proceeding first made against any Insured during the Policy
Period for a Data Breach or a Security Breach.
Payment Card Liabilities & Costs
To indemnify the Insured Organization for PCI Fines, Expenses and Costs which it is
legally obligated to pay because of a Claim first made against any Insured during the
Policy Period.
F00731
022019 ed. Page 1 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
First Party Data & Network Loss
To indemnify the Insured Organization for:
Business Interruption Loss
Business Interruption Loss that the Insured Organization sustains as a result
of a Security Breach or System Failure that the Insured first discovers during
the Policy Period.
Dependent Business Interruption Loss
Dependent Business Loss that the Insured Organization sustains as a result
of a Dependent Security Breach or a Dependent System Failure that the
Insured first discovers during the Policy Period.
Cyber Extortion Loss
Cyber Extortion Loss that the Insured Organization incurs as a result of an
Extortion Threat first made against the Insured Organization during the Policy
Period.
Data Recovery Costs
Data Recovery Costs that the Insured Organization incurs as a direct result of
a Security Breach or System Failure that the Insured first discovers during the
Policy Period.
eCrime
To indemnify the Insured Organization for any direct financial loss sustained resulting
from:
1. Fraudulent Instruction;
2. Funds Transfer Fraud; or
3. Telephone Fraud;
that the Insured first discovers during the Policy Period.
Criminal Reward
To indemnify the Insured Organization for Criminal Reward Funds.
DEFINITIONS
Additional Insured means any person or entity that the Insured Organization has agreed in
writing to add as an Additional Insured under this Policy prior to the commission of any act for
which such person or entity would be provided coverage under this Policy, but only to the extent
the Insured Organization would have been liable and coverage would have been afforded under
the terms and conditions of this Policy had such Claim been made against the Insured
Organization.
F00731
022019 ed. Page 2 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Breach Notice Law means any statute or regulation that requires notice to persons whose
personal information was accessed or reasonably may have been accessed by an unauthorized
person. Breach Notice Law also includes any statute or regulation requiring notice of a Data
Breach to be provided to governmental or regulatory authorities.
Breach Response Costs means the following fees and costs incurred by the Insured
Organization with the Underwriters' prior written consent in response to an actual or reasonably
suspected Data Breach or Security Breach:
1. for an attorney to provide necessary legal advice to the Insured Organization to
evaluate its obligations pursuant to Breach Notice Laws or a Merchant
Services Agreement;
2. for a computer security expert to determine the existence, cause and scope of an
actual or reasonably suspected Data Breach, and if such Data Breach is
actively in progress on the Insured Organization's Computer Systems, to
assist in containing it;
3. for a PCI Forensic Investigator to investigate the existence and extent of an
actual or reasonably suspected Data Breach involving payment card data and
for a Qualified Security Assessor to certify and assist in attesting to the Insured
Organization's PCI compliance, as required by a Merchant Services
Agreement;
4. to notify those individuals whose Personally Identifiable Information was
potentially impacted by a Data Breach;
5. to provide a call center to respond to inquiries about a Data Breach;
6. to provide a credit monitoring, identity monitoring or other personal fraud or loss
prevention solution, to be approved by the Underwriters, to individuals whose
Personally Identifiable Information was potentially impacted by a Data
Breach; and
7. public relations and crisis management costs directly related to mitigating harm
to the Insured Organization which are approved in advance by the Underwriters
in their discretion.
Breach Response Costs will not include any internal salary or overhead expenses of
the Insured Organization.
Business Interruption Loss means:
1. Income Loss;
2. Forensic Expenses; and
3. Extra Expense;
actually sustained during the Period of Restoration as a result of the actual interruption
of the Insured Organization's business operations caused by a Security Breach or
System Failure. Coverage for Business Interruption Loss will apply only after the
Waiting Period has elapsed.
F00731
022019 ed. Page 3 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Business Interruption Loss will not include (i) loss arising out of any liability to any third
party; (ii) legal costs or legal expenses; (iii) loss incurred as a result of unfavorable
business conditions; (iv) loss of market or any other consequential loss; (v) Dependent
Business Loss; or(vi) Data Recovery Costs.
Claim means:
1. a written demand received by any Insured for money, services, or any non-
monetary or injunctive relief;
2. a written request for mediation or arbitration received by any Insured;
3. a civil proceeding against any Insured commenced by service of a complaint or
similar proceeding;
4. a written request to toll or waive any applicable statute of limitations;
5. with respect to coverage provided under the Regulatory Defense & Penalties
insuring agreement only, institution of a Regulatory Proceeding against any
Insured; and
Multiple Claims arising from the same or a series of related, repeated or continuing acts,
errors, omissions or events will be considered a single Claim for the purposes of this
Policy. All such Claims will be deemed to have been made at the time of the first such
Claim.
Claims Expenses means:
1. all reasonable and necessary legal costs and expenses resulting from the
investigation, defense and appeal of a Claim, if incurred by the Underwriters, or
by the Insured with the prior written consent of the Underwriters; and
2. the premium cost for appeal bonds for covered judgments or bonds to release
property used to secure a legal obligation; provided the Underwriters will have no
obligation to appeal or to obtain bonds.
Claims Expenses will not include any salary, overhead, or other charges by the
Insured for any time spent in cooperating in the defense and investigation of any Claim,
or costs to comply with any regulatory orders, settlements or judgments.
Computer Systems means computers, any software residing on such computers and any
associated devices or equipment (including computers, hardware, software and input and output
devices which are part of an industrial control system, including a supervisory control and data
acquisition (SCADA)system):
1. operated by and either owned by or leased to the Insured Organization; or
2. with respect to coverage under Part 4. of the Media, Tech, Data & Network
Liability insuring agreement, as well as the Breach Response, Regulatory
Defense & Penalties and Payment Card Liabilities & Costs insuring agreements,
operated by a third party pursuant to written contract with the Insured
Organization and used for the purpose of providing hosted computer application
services to the Insured Organization or for processing, maintaining, hosting or
storing the Insured Organization's electronic data.
F00731
022019 ed. Page 4 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Continuity Date means:
1. the Continuity Date listed in the Declarations; and
2. with respect to any Subsidiaries acquired after the Continuity Date listed in the
Declarations, the date the Named Insured acquired such Subsidiary.
Control Group means any principal, partner, corporate officer, director, general counsel (or most
senior legal counsel) or risk manager of the Insured Organization and any individual in a
substantially similar position.
Criminal Reward Funds means any amount offered and paid by the Insured Organization with
the Underwriters' prior written consent for information that leads to the arrest and conviction of
any individual(s) committing or trying to commit any illegal act related to any coverage under this
Policy; but will not include any amount based upon information provided by the Insured, the
Insured's auditors or any individual hired or retained to investigate the illegal acts. All Criminal
Reward Funds offered pursuant to this Policy must expire no later than 6 months following the
end of the Policy Period.
Cyber Extortion Loss means:
1. any Extortion Payment that has been made by or on behalf of the Insured
Organization with the Underwriters' prior written consent to prevent or terminate
an Extortion Threat; and
2. reasonable and necessary expenses incurred by the Insured Organization with
the Underwriters' prior written consent to prevent or respond to an Extortion
Threat.
Damages means a monetary judgment, award or settlement, including any award of prejudgment
or post-judgment interest. With the prior written consent of the Underwriters, Damages also
include the direct net cost of providing any future service credits offered by the Insured
Organization in lieu of a monetary payment.
Damages will not include:
1. future profits, restitution, disgorgement of unjust enrichment or profits by an
Insured, or the costs of complying with orders granting injunctive or equitable
relief;
2. return or offset of fees, charges or commissions charged by or owed to an
Insured for goods or services already provided or contracted to be provided;
3. taxes or loss of tax benefits;
4. fines, sanctions or penalties against any Insured;
5. punitive or exemplary damages or any damages which are a multiple of
compensatory damages, unless insurable by law in any applicable venue that
most favors coverage for such punitive, exemplary or multiple damages;
6. discounts, coupons, prizes, awards or other incentives offered to the Insured's
customers or clients;
F00731
022019 ed. Page 5 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
7. liquidated damages, but only to the extent that such damages exceed the
amount for which the Insured would have been liable in the absence of such
liquidated damages agreement;
8. fines, costs or other amounts an Insured is responsible to pay under a Merchant
Services Agreement; or
9. any amounts for which the Insured is not liable, or for which there is no legal
recourse against the Insured.
Data means any software or electronic data that exists in Computer Systems and that is subject
to regular back-up procedures.
Data Breach means the theft, loss, or Unauthorized Disclosure of Personally Identifiable
Information or Third Party Information that is in the care, custody or control of the Insured
Organization or a third party for whose theft, loss or Unauthorized Disclosure of Personally
Identifiable Information or Third Party Information the Insured Organization is liable.
Data $ Network Wrongful Act means:
1. a Data Breach;
2. a Security Breach;
3. failure to timely disclose a Data Breach or Security Breach; or
4. a Privacy Policy Violation.
Data Recovery Costs means the reasonable and necessary costs incurred by the Insured
Organization to regain access to, replace, or restore Data, or if Data cannot reasonably be
accessed, replaced, or restored, then the reasonable and necessary costs incurred by the
Insured Organization to reach this determination.
Data Recovery Costs will not include: (i) the monetary value of profits, royalties, or lost
market share related to Data, including but not limited to trade secrets or other
proprietary information or any other amount pertaining to the value of Data; (ii) legal costs
or legal expenses; (iii) loss arising out of any liability to any third party; or (iv) Cyber
Extortion Loss.
Dependent Business means any entity that is not a part of the Insured Organization but which
provides necessary products or services to the Insured Organization pursuant to a written
contract.
Dependent Business Loss means:
1. Income Loss; and
2. Extra Expense;
actually sustained during the Period of Restoration as a result of an actual interruption
of the Insured Organization's business operations caused by a Dependent Security
Breach or Dependent System Failure. Coverage for Dependent Business Loss will
apply only after the Waiting Period has elapsed.
F00731
022019 ed. Page 6 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Dependent Business Loss will not include (i) loss arising out of any liability to any third
party; (ii) legal costs or legal expenses; (iii) loss incurred as a result of unfavorable
business conditions; (iv) loss of market or any other consequential loss; (v) Business
Interruption Loss; or(vi) Data Recovery Costs.
Dependent Security Breach means a failure of computer security to prevent a breach of
computer systems operated by a Dependent Business.
Dependent System Failure means an unintentional and unplanned interruption of computer
systems operated by a Dependent Business.
Dependent System Failure will not include any interruption of computer systems
resulting from (i) a Dependent Security Breach, or (ii) the interruption of computer
systems that are not operated by a Dependent Business.
Digital Currency means a type of digital currency that:
1. requires cryptographic techniques to regulate the generation of units of currency
and verify the transfer thereof;
2. is both stored and transferred electronically; and
3. operates independently of a central bank or other central authority.
Extortion Payment means Money, Digital Currency, marketable goods or services demanded
to prevent or terminate an Extortion Threat.
Extortion Threat means a threat to:
1. alter, destroy, damage, delete or corrupt Data;
2. perpetrate the Unauthorized Access or Use of Computer Systems;
3. prevent access to Computer Systems or Data;
4. steal, misuse or publicly disclose Data, Personally Identifiable Information or
Third Party Information;
5. introduce malicious code into Computer Systems or to third party computer
systems from Computer Systems; or
6. interrupt or suspend Computer Systems;
unless an Extortion Payment is received from or on behalf of the Insured
Organization.
Extra Expense means reasonable and necessary expenses incurred by the Insured
Organization during the Period of Restoration to minimize, reduce or avoid Income Loss, over
and above those expenses the Insured Organization would have incurred had no Security
Breach, System Failure, Dependent Security Breach or Dependent System Failure occurred.
Financial Institution means a bank, credit union, saving and loan association, trust company or
other licensed financial service, securities broker-dealer, mutual fund, or liquid assets fund or
similar investment company where the Insured Organization maintains a bank account.
F00731
022019 ed. Page 7 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Forensic Expenses means reasonable and necessary expenses incurred by the Insured
Organization to investigate the source or cause of a Business Interruption Loss.
Fraudulent Instruction means the transfer, payment or delivery of Money or Securities by an
Insured as a result of fraudulent written, electronic, telegraphic, cable, teletype or telephone
instructions provided by a third party, that is intended to mislead an Insured through the
misrepresentation of a material fact which is relied upon in good faith by such Insured.
Fraudulent Instruction will not include loss arising out of:
1. fraudulent instructions received by the Insured which are not first authenticated
via a method other than the original means of request to verify the authenticity or
validity of the request;
2. any actual or alleged use of credit, debit, charge, access, convenience, customer
identification or other cards;
3. any transfer involving a third party who is not a natural person Insured, but had
authorized access to the Insured's authentication mechanism;
4. the processing of, or the failure to process, credit, check, debit, personal
identification number debit, electronic benefit transfers or mobile payments for
merchant accounts;
5. accounting or arithmetical errors or omissions, or the failure, malfunction,
inadequacy or illegitimacy of any product or service;
6. any liability to any third party, or any indirect or consequential loss of any kind;
7. any legal costs or legal expenses; or
8. proving or establishing the existence of Fraudulent Instruction.
Funds Transfer Fraud means the loss of Money or Securities contained in a Transfer Account
at a Financial Institution resulting from fraudulent written, electronic, telegraphic, cable, teletype
or telephone instructions by a third party issued to a Financial Institution directing such
institution to transfer, pay or deliver Money or Securities from any account maintained by the
Insured Organization at such institution, without the Insured Organization's knowledge or
consent.
Funds Transfer Fraud will not include any loss arising out of:
1. the type or kind covered by the Insured Organization's financial institution bond
or commercial crime policy;
2. any actual or alleged fraudulent, dishonest or criminal act or omission by, or
involving, any natural person Insured;
3. any indirect or consequential loss of any kind;
4. punitive, exemplary or multiplied damages of any kind or any fines, penalties or
loss of any tax benefit;
5. any liability to any third party, except for direct compensatory damages arising
directly from Funds Transfer Fraud;
F00731
022019 ed. Page 8 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
6. any legal costs or legal expenses; or proving or establishing the existence of
Funds Transfer Fraud;
7. the theft, disappearance, destruction of, unauthorized access to, or unauthorized
use of confidential information, including a PIN or security code;
8. any forged, altered or fraudulent negotiable instruments, securities, documents or
instructions; or
9. any actual or alleged use of credit, debit, charge, access, convenience or other
cards or the information contained on such cards.
Income Loss means an amount equal to:
1. net profit or loss before interest and tax that the Insured Organization would
have earned or incurred; and
2. continuing normal operating expenses incurred by the Insured Organization
(including payroll), but only to the extent that such operating expenses must
necessarily continue during the Period of Restoration.
Individual Contractor means any natural person who performs labor or service for the Insured
Organization pursuant to a written contract or agreement with the Insured Organization. The
status of an individual as an Individual Contractor will be determined as of the date of an
alleged act, error or omission by any such Individual Contractor.
Insured means:
1. the Insured Organization;
2. any director or officer of the Insured Organization, but only with respect to the
performance of his or her duties as such on behalf of the Insured Organization;
3. an employee (including a part time, temporary, leased or seasonal employee or
volunteer) or Individual Contractor of the Insured Organization, but only for
work done while acting within the scope of his or her employment and related to
the conduct of the Insured Organization's business;
4. a principal if the Named Insured is a sole proprietorship, or a partner if the
Named Insured is a partnership, but only with respect to the performance of his
or her duties as such on behalf of the Insured Organization;
5. any person who previously qualified as an Insured under parts 2. through 4., but
only with respect to the performance of his or her duties as such on behalf of the
Insured Organization;
6. an Additional Insured, but only as respects Claims against such person or
entity for acts, errors or omissions of the Insured Organization;
7. the estate, heirs, executors, administrators, assigns and legal representatives of
any Insured in the event of such Insured's death, incapacity, insolvency or
bankruptcy, but only to the extent that such Insured would otherwise be provided
coverage under this Policy; and
F00731
022019 ed. Page 9 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
8. the lawful spouse, including any natural person qualifying as a domestic partner
of any Insured, but solely by reason of any act, error or omission of an Insured
other than such spouse or domestic partner.
Insured Organization means the Named Insured and any Subsidiaries.
Loss means Breach Response Costs, Business Interruption Loss, Claims Expenses,
Criminal Reward Funds, Cyber Extortion Loss, Damages, Data Recovery Costs, Dependent
Business Loss, PCI Fines, Expenses and Costs, Penalties, loss covered under the eCrime
insuring agreement and any other amounts covered under this Policy.
Any Loss arising from the same or a series of related, repeated or continuing acts,
errors, omissions, incidents or events will be considered a single Loss for the purposes
of this Policy.
With respect to the Breach Response and First Party Data & Network Loss insuring
agreements, all acts, errors, omissions, incidents or events (or series of related, repeated
or continuing acts, errors, omissions, incidents or events) giving rise to Loss in
connection with such insuring agreements will be deemed to have been discovered at the
time the first such act, error, omission, incident or event is discovered.
Media Activities means creating, displaying, broadcasting, disseminating or releasing Media
Material by or on behalf of the Insured Organization to the public, including any blog, webcasts,
websites, broadcast or cable stations, or social media web pages, created and maintained by or
on behalf of the Insured Organization.
Media Material means any information, including words, sounds, numbers, images or graphics,
but will not include computer software or the actual goods, products or services described,
illustrated or displayed in such Media Material.
Media Wrongful Act means one or more of the following acts committed on or after the
Retroactive Date and before the end of the Policy Period in the course of the Insured
Organization's performance of Media Activities, Professional Services or Tech Services:
1. defamation, libel, slander, product disparagement, trade libel, infliction of
emotional distress, outrage, outrageous conduct, or other tort related to
disparagement or harm to the reputation or character of any person or
organization;
2. a violation of the rights of privacy of an individual, including false light, intrusion
upon seclusion and public disclosure of private facts;
3. invasion or interference with an individual's right of publicity, including
misappropriation of any name, persona, voice or likeness for commercial
advantage;
4. false arrest, detention or imprisonment;
5. invasion of or interference with any right to private occupancy, including trespass,
wrongful entry or wrongful eviction;
6. plagiarism, piracy or misappropriation of ideas under implied contract;
7. infringement of copyright;
F00731
022019 ed. Page 10 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
8. infringement of trade dress, domain name, title or slogan, or the dilution or
infringement of trademark or service mark, or improper deep-linking or framing or
infringement of domain name including cybersquatting violations;
9. negligence regarding the content of any Media Activities, including harm caused
through any reliance or failure to rely upon such content;
10. misappropriation of a trade secret;
11. unfair competition including a violation of Section 43(a) of the Lanham Act, but
only if alleged in conjunction with and arising out of any of the acts listed in
paragraphs 7. or 8. above.
Merchant Services Agreement means any agreement between an Insured and a financial
institution, credit/debit card company, credit/debit card processor or independent service operator
enabling an Insured to accept credit card, debit card, prepaid card or other payment cards for
payments or donations.
Money means a medium of exchange in current use authorized or adopted by a domestic or
foreign government as a part of its currency.
Named Insured means the Named Insured listed in the Declarations.
PCI Fines, Expenses and Costs means the monetary amount owed by the Insured
Organization under the terms of a Merchant Services Agreement as a direct result of a
suspected Data Breach. With the prior consent of the Underwriters, PCI Fines, Expenses and
Costs includes reasonable and necessary legal costs and expenses incurred by the Insured
Organization to appeal or negotiate an assessment of such monetary amount. PCI Fines,
Expenses and Costs will not include any charge backs, interchange fees, discount fees or other
fees unrelated to a Data Breach.
Penalties means:
1. any monetary civil fine or penalty payable to a governmental entity that was
imposed in a Regulatory Proceeding; and
2. amounts which the Insured is legally obligated to deposit in a fund as equitable
relief for the payment of consumer claims due to an adverse judgment or
settlement of a Regulatory Proceeding (including such amounts required to be
paid into a "Consumer Redress Fund");
but will not include: (i) costs to remediate or improve Computer Systems; (ii) costs to
establish, implement, maintain, improve or remediate security or privacy practices,
procedures, programs or policies; (iii) audit, assessment, compliance or reporting costs;
or (iv) costs to protect the confidentiality, integrity and/or security of Personally
Identifiable Information or other information.
The insurability of Penalties will be in accordance with the law in the applicable venue
that most favors coverage for such Penalties.
Period of Restoration means the 180-day period of time that begins upon the actual and
necessary interruption of the Insured Organization's business operations.
F00731
022019 ed. Page 11 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Personally Identifiable Information means:
1. any information concerning an individual that is defined as personal information
under any Breach Notice Law; and
2. an individual's drivers license or state identification number, social security
number, unpublished telephone number, and credit, debit or other financial
account numbers in combination with associated security codes, access codes,
passwords or PINs; if such information allows an individual to be uniquely and
reliably identified or contacted or allows access to the individual's financial
account or medical record information.
but will not include information that is lawfully made available to the general public.
Policy Period means the period of time between the inception date listed in the Declarations and
the effective date of termination, expiration or cancellation of this Policy and specifically excludes
any Optional Extension Period or any prior policy period or renewal period.
Privacy Policy means the Insured Organization's public declaration of its policy for collection,
use, disclosure, sharing, dissemination and correction or supplementation of, and access to
Personally Identifiable Information.
Privacy Policy Violation means the failure by the Insured to comply with that part of a Privacy
Policy that specifically:
1. prohibits or restricts the Insured Organization's disclosure, sharing or selling of
Personally Identifiable Information;
2. requires the Insured Organization to provide an individual access to Personally
Identifiable Information or to correct incomplete or inaccurate Personally
Identifiable Information after a request is made;
3. mandates procedures and requirements to prevent the loss of Personally
Identifiable Information;
4. prevents or prohibits improper, intrusive or wrongful collection of Personally
Identifiable Information from another person;
5. requires notice to a person of the Insured Organization's collection or use of, or
the nature of the collection or use of his or her Personally Identifiable
Information; or
6. provides a person with the ability to assent to or withhold assent for(e.g. opt-in or
opt-out) the Insured Organization's collection or use of his or her Personally
Identifiable Information;
provided the Insured Organization has in force, at the time of such failure, a Privacy
Policy that addresses those subsections above that are relevant to such Claim.
Professional Services means professional services performed for others by or on behalf of the
Insured Organization for a fee.
Professional Services will not include activities performed by or on behalf of the
Insured Organization as an accountant, architect, surveyor, health care provider,
lawyer, insurance or real estate agent or broker, or civil or structural engineer.
F00731
022019 ed. Page 12 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Regulatory Proceeding means a request for information, civil investigative demand, or civil
proceeding brought by or on behalf of any federal, state, local or foreign governmental entity in
such entity's regulatory or official capacity.
Retroactive Date means the applicable date listed in the Declarations.
Securities means negotiable and non-negotiable instruments or contracts representing either
Money or tangible property that has intrinsic value.
Security Breach means a failure of computer security to prevent:
1. Unauthorized Access or Use of Computer Systems, including Unauthorized
Access or Use resulting from the theft of a password from a Computer System
or from any Insured;
2. a denial of service attack affecting Computer Systems;
3. with respect to coverage under the Liability insuring agreements, a denial of
service attack affecting computer systems that are not owned, operated or
controlled by an Insured; or
4. infection of Computer Systems by malicious code or transmission of malicious
code from Computer Systems.
Subsidiary means any entity:
1. which, on or prior to the inception date of this Policy, the Named Insured owns,
directly or indirectly, more than 50% of the outstanding voting securities
("Management Control"); and
2. which the Named Insured acquires Management Control after the inception date of
this Policy; provided that:
(i) the revenues of such entity do not exceed 15% of the Named Insured's
annual revenues; or
(ii) if the revenues of such entity exceed 15% of the Named Insured's
annual revenues, then coverage under this Policy will be afforded for a
period of 60 days, but only for any Claim that arises out of any act, error,
omission, incident or event first occurring after the entity becomes so
owned. Coverage beyond such 60 day period will only be available if the
Named Insured gives the Underwriters written notice of the acquisition,
obtains the written consent of Underwriters to extend coverage to the
entity beyond such 60 day period and agrees to pay any additional
premium required by Underwriters.
This Policy provides coverage only for acts, errors, omissions, incidents or events that
occur while the Named Insured has Management Control over an entity.
System Failure means an unintentional and unplanned interruption of Computer Systems.
System Failure will not include any interruption of computer systems resulting from (i) a
Security Breach, or(ii)the interruption of any third party computer system.
F00731
022019 ed. Page 13 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Tech Products means a computer or telecommunications hardware or software product, or
related electronic product, that is created, manufactured or developed by the Insured
Organization for others, or distributed, licensed, leased or sold by the Insured Organization to
others, for compensation, including software updates, service packs and other maintenance
releases provided for such products.
Tech & Professional Services Wrongful Act means any negligent act, error, omission,
misstatement, misleading statement, misrepresentation or unintentional breach of a contractual
obligation by the Insured, or by any person or entity for whom the Insured is legally liable, in
rendering or failing to render Professional Services or Tech Services that occurs on or after the
Retroactive Date and before the end of the Policy Period, but does not mean a Media
Wrongful Act.
Tech Product Wrongful Act means:
1. any negligent act, error, omission, misstatement, misleading statement,
misrepresentation or unintentional breach of a contractual obligation by the
Insured that results in the failure of Tech Products to perform the function or
serve the purpose intended; or
2. software copyright infringement by the Insured with respect to Tech Products;
that occurs on or after the Retroactive Date and before the end of the Policy Period.
Tech Services means computer, cloud computing, and electronic technology services, including:
1. data processing, software as a service (SaaS), platform as a service (PaaS),
infrastructure as a service (laaS), network as a service (NaaS);
2. data and application hosting, computer systems analysis, and technology
consulting and training; or
3. custom software programming for a specific client of the Insured Organization
and, computer and software systems installation and integration;
performed by the Insured, or by others acting under the Insured Organization's trade
name, for others for a fee.
Telephone Fraud means the act of a third party gaining access to and using the Insured
Organization's telephone system in an unauthorized manner.
Third Party Information means any trade secret, data, design, interpretation, forecast, formula,
method, practice, credit or debit card magnetic strip information, process, record, report or other
item of information of a third party not insured under this Policy which is not available to the
general public.
Transfer Account means an account maintained by the Insured Organization at a Financial
Institution from which the Insured Organization can initiate the transfer, payment or delivery of
Money or Securities.
Unauthorized Access or Use means the gaining of access to or use of Computer Systems by
an unauthorized person(s)or the use of Computer Systems in an unauthorized manner.
Unauthorized Disclosure means the disclosure of (including disclosure resulting from phishing)
or access to information in a manner that is not authorized by the Insured Organization and is
without knowledge of, consent or acquiescence of any member of the Control Group.
F00731
022019 ed. Page 14 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Waiting Period means the period of time that begins upon the actual interruption of the Insured
Organization's business operations caused by a Security Breach, System Failure, Dependent
Security Breach or Dependent System Failure, and ends after the elapse of the number of
hours listed as the Waiting Period in the Declarations.
EXCLUSIONS
The coverage under this Policy will not apply to any Loss arising out of:
Bodily Injury or Property Damage
1. physical injury, sickness, disease or death of any person, including any mental
anguish or emotional distress resulting from such physical injury, sickness,
disease or death; or
2. physical injury to or destruction of any tangible property, including the loss of use
thereof; but electronic data will not be considered tangible property;
Deceptive Business Practices, Antitrust&Consumer Protection
any actual or alleged false, deceptive or unfair trade practices, antitrust violation, restraint
of trade, unfair competition (except as provided under part 3. of the Media, Tech, Data &
Network Liability insuring agreement), violation of consumer protection law, false,
deceptive or misleading advertising, inaccurate cost estimates or failure of goods or
services to conform with any represented quality or performance, or violation of the
Sherman Antitrust Act, the Clayton Act, or the Robinson-Patman Act; but this exclusion
will not apply to:
1. the Breach Response insuring agreement; or
2. coverage for a Data Breach or Security Breach, provided no member of the
Control Group participated or colluded in such Data Breach or Security
Breach;
Distribution of Information
the distribution of unsolicited email, text messages, direct mail, facsimiles or other
communications, wire tapping, audio or video recording, or telemarketing, if such
distribution, wire tapping, recording or telemarketing is done by or on behalf of the
Insured Organization; but this exclusion will not apply to Claims Expenses incurred in
defending the Insured against allegations of unlawful audio or video recording;
Prior Known Acts & Prior Noticed Claims
1. any act, error, omission, incident or event committed or occurring prior to the
inception date of this Policy if any member of the Control Group on or before the
Continuity Date knew or could have reasonably foreseen that such act, error or
omission, incident or event might be expected to be the basis of a Claim or
Loss;
2. any Claim, Loss, incident or circumstance for which notice has been provided
under any prior policy of which this Policy is a renewal or replacement;
F00731
022019 ed. Page 15 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Racketeering, Benefit Plans, Employment Liability & Discrimination
1. any actual or alleged violation of the Organized Crime Control Act of 1970
(commonly known as Racketeer Influenced and Corrupt Organizations Act or
RICO), as amended;
2. any actual or alleged acts, errors or omissions related to any of the Insured
Organization's pension, healthcare, welfare, profit sharing, mutual or investment
plans, funds or trusts;
3. any employer-employee relations, policies, practices, acts or omissions, or any
actual or alleged refusal to employ any person, or misconduct with respect to
employees; or
4. any actual or alleged discrimination;
but this exclusion will not apply to coverage under the Breach Response insuring
agreement or coverage for a Data Breach or Security Breach, provided no member of
the Control Group participated or colluded in such Data Breach or Security Breach;
Sale or Ownership of Securities &Violation of Securities Laws
1. the ownership, sale or purchase of, or the offer to sell or purchase stock or other
securities; or
2. an actual or alleged violation of a securities law or regulation;
Criminal, Intentional or Fraudulent Acts
any criminal, dishonest, fraudulent, or malicious act or omission, or intentional or knowing
violation of the law, if committed by an Insured, or by others if the Insured colluded or
participated in any such conduct or activity; but this exclusion will not apply to:
1. Claims Expenses incurred in defending any Claim alleging the foregoing until
there is a final non-appealable adjudication establishing such conduct; or
2. with respect to a natural person Insured, if such Insured did not personally
commit, participate in or know about any act, error, omission, incident or event
giving rise to such Claim or Loss.
For purposes of this exclusion, only acts, errors, omissions or knowledge of a member of
the Control Group will be imputed to the Insured Organization;
Patent& Misappropriation of Information
1. infringement, misuse or abuse of patent or patent rights;
2. misappropriation of trade secret arising out of or related to Tech Products or any
other products;
3. with respect to any Data & Network Wrongful Act, misappropriation of any
Third Party Information (i) by or on behalf of the Insured Organization, or (ii)
by any other person or entity if such misappropriation is done with the
knowledge, consent or acquiescence of a member of the Control Group; or
F00731
022019 ed. Page 16 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
4. disclosure, misuse or misappropriation of any ideas, trade secrets or confidential
information that came into the possession of any person or entity prior to the date
he or she became an Insured or Subsidiary of the Insured Organization;
Governmental Actions
a Claim brought by or on behalf of any state, federal, local or foreign governmental entity,
in such entity's regulatory or official capacity; but this exclusion will not apply to the
Regulatory Defense & Penalties insuring agreement, or any Claim made against the
Insured Organization by a governmental entity solely in its capacity as a customer of
the Insured Organization;
Other Insureds & Related Enterprises
a Claim made by or on behalf of:
1. any Insured; but this exclusion will not apply to a Claim made by an individual
that is not a member of the Control Group for a Data & Network Wrongful Act,
or a Claim made by an Additional Insured; or
2. any business enterprise in which any Insured has greater than 15% ownership
interest or made by any parent company or other entity which owns more than
15% of the Named Insured;
Trading Losses & Loss of Money
1. any trading losses, trading liabilities or change in value of accounts;
2. any loss, transfer or theft of monies, securities or tangible property of the Insured
or others in the care, custody or control of the Insured Organization; or
3. the monetary value of any transactions or electronic fund transfers by or on
behalf of the Insured which is lost, diminished, or damaged during transfer from,
into or between accounts;
but this exclusion will not apply to coverage under the eCrime insuring agreement;
Contractual
with respect to coverage under parts 1. and 3. of the Media, Tech, Data & Network
Liability insuring agreement:
any obligation the Insured has under contract; but this exclusion will not apply to:
1. the obligation to perform Professional Services or Tech Services;
2. a Claim for misappropriation of ideas under implied contract, or
3. to the extent the Insured would have been liable in the absence of such contract;
Retroactive Date
any related or continuing act, error, omission, misstatement, misleading statement,
misrepresentation, unintentional breach of a contractual obligation, incident or event
where the first such act, error, omission, misstatement, misleading statement,
F00731
022019 ed. Page 17 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
misrepresentation or unintentional breach of a contractual obligation, incident or event
was committed or occurred prior to the Retroactive Date;
Recall
any costs or expenses incurred or to be incurred by the Insured or others for the
reprinting, reposting, recall, inspection, repair, replacement, removal or disposal of any
Tech Products, Media Material or work product, including when resulting from or
incorporating the results of Professional Services or Tech Services; but this exclusion
will not apply to the resulting loss of use of such Tech Products, Media Material or work
product resulting from or incorporating the results of Professional Services or Tech
Services;
Infrastructure Failure
failure or malfunction of satellites or of power, utility, mechanical or telecommunications
(including internet) infrastructure or services that are not under the Insured
Organization's direct operational control;
Licensing Bodies &Joint Ventures
1. the actual or alleged obligation to make licensing fee or royalty payments; or any
Claim brought by or on behalf of any intellectual property licensing bodies or
organizations;
2. any Claim made by or on behalf of any independent contractor, joint venturer or
venture partner arising out of or resulting from disputes over ownership of rights
in Media Material or services provided by such independent contractor, joint
venturer or venture partner;
Over-Redemption
1. any actual or alleged gambling, contest, lottery, promotional game or other game
of chance; or
2. the value of coupons, price discounts, prizes, awards, or any other valuable
consideration given in excess of the total contracted or expected amount;
First Party Data & Network Loss
with respect to the First Party Data & Network Loss insuring agreements:
1. seizure, nationalization, confiscation, or destruction of property or data by order
of any governmental or public authority;
2. costs or expenses incurred by the Insured to identify or remediate software
program errors or vulnerabilities or update, replace, restore, assemble,
reproduce, recollect or enhance data or Computer Systems to a level beyond
that which existed prior to a Security Breach, System Failure, Dependent
Security Breach, Dependent System Failure or Extortion Threat;
3. fire, flood, earthquake, volcanic eruption, explosion, lightning, wind, hail, tidal
wave, landslide, act of God or other physical event.
F00731
022019 ed. Page 18 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
LIMIT OF •
The Policy Aggregate Limit of Liability listed in the Declarations (the "Policy Aggregate Limit of
Liability") is the Underwriters' combined total limit of liability for all Loss payable under this
Policy.
The limit of liability payable under each insuring agreement will be an amount equal to the Policy
Aggregate Limit of Liability unless another amount is listed in the Declarations. Such amount
is the aggregate amount payable under this Policy pursuant to such insuring agreement and is
part of, and not in addition to, the Policy Aggregate Limit of Liability.
All Dependent Business Loss payable under this Policy is part of and not in addition to the
Business Interruption Loss limit listed in the Declarations.
The Underwriters will not be obligated to pay any Loss, or to defend any Claim, after the Policy
Aggregate Limit of Liability has been exhausted, or after deposit of the Policy Aggregate
Limit of Liability in a court of competent jurisdiction.
RETENTIONS
The Retention listed in the Declarations applies separately to each act, error, omission, incident,
event or related acts, errors, omissions, incidents or events giving rise to a Claim or Loss. The
Retention will be satisfied by monetary payments by the Named Insured of covered Loss under
each insuring agreement. If any Loss arising out of an incident or Claim is subject to more than
one Retention, the Retention for each applicable insuring agreement will apply to such Loss,
provided that the sum of such Retention amounts will not exceed the largest applicable Retention
amount.
Coverage for Business Interruption Loss and Dependent Business Loss will apply after the
Waiting Period has elapsed and the Underwriters will then indemnify the Named Insured for all
Business Interruption Loss and Dependent Business Loss sustained during the Period of
Restoration in excess of the Retention.
Satisfaction of the applicable Retention is a condition precedent to the payment of any Loss
under this Policy, and the Underwriters will be liable only for the amounts in excess of such
Retention.
OPTIONAL EXTENSIONPERIOD
Upon non-renewal or cancellation of this Policy for any reason except the non-payment of premium,
the Named Insured will have the right to purchase, for additional premium in the amount of the
Optional Extension Premium percentage listed in the Declarations of the full Policy Premium
listed in the Declarations, an Optional Extension Period for the period of time listed in the
Declarations. Coverage provided by such Optional Extension Period will only apply to Claims first
made against any Insured during the Optional Extension Period and reported to the Underwriters
during the Optional Extension Period, and arising out of any act, error or omission committed on
or after the Retroactive Date (if applicable) and before the end of the Policy Period. In order for
the Named Insured to invoke the Optional Extension Period option, the payment of the additional
premium for the Optional Extension Period must be paid to the Underwriters within 60 days of the
termination of this Policy.
The purchase of the Optional Extension Period will in no way increase the Policy Aggregate Limit
of Liability or any sublimit of liability. At the commencement of the Optional Extension Period the
entire premium will be deemed earned, and in the event the Named Insured terminates the
F00731
022019 ed. Page 19 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Optional Extension Period for any reason prior to its natural expiration, the Underwriters will not
be liable to return any premium paid for the Optional Extension Period.
All notices and premium payments with respect to the Optional Extension Period option will be
directed to the Underwriters through entity listed for Administrative Notice in the Declarations.
GENERAL CONDITIONS
Notice of Claim or Loss
The Insured must notify the Underwriters of any Claim as soon as practicable, but in no
event later than: (i) 60 days after the end of the Policy Period; or (ii) the end of the
Optional Extension Period (if applicable). Notice must be provided through the contacts
listed for Notice of Claim, Loss or Circumstance in the Declarations.
With respect to Breach Response Costs, the Insured must notify the Underwriters of
any actual or reasonably suspected Data Breach or Security Breach as soon as
practicable after discovery by the Insured, but in no event later than 60 days after the
end of the Policy Period. Notice must be provided through the contacts listed for Notice
of Claim, Loss or Circumstance in the Declarations. Notice of an actual or reasonably
suspected Data Breach or Security Breach in conformance with this paragraph will also
constitute notice of a circumstance that could reasonably be the basis for a Claim.
With respect to Cyber Extortion Loss, the Named Insured must notify the Underwriters
via the email address listed in the Notice of Claim, Loss or Circumstance in the
Declarations as soon as practicable after discovery of an Extortion Threat but no later
than 60 days after the end of the Policy Period. The Named Insured must obtain the
Underwriters' consent prior to incurring Cyber Extortion Loss.
With respect to Data Recovery Costs, Business Interruption Loss and Dependent
Business Loss the Named Insured must notify the Underwriters through the contacts
for Notice of Claim, Loss or Circumstance in the Declarations as soon as practicable after
discovery of the circumstance, incident or event giving rise to such loss. The Named
Insured will provide the Underwriters a proof of Data Recovery Costs, Business
Interruption Loss and Dependent Business Loss, and this Policy will cover the
reasonable and necessary costs, not to exceed USD 50,000, that the Named Insured
incurs to contract with a third party to prepare such proof. All loss described in this
paragraph must be reported, and all proofs of loss must be provided, to the Underwriters
no later than 6 months after the end of the Policy Period.
The Named Insured must notify the Underwriters of any loss covered under the eCrime
insuring agreement as soon as practicable, but in no event later than 60 days after the
end of the Policy Period. Notice must be provided through the contacts listed for Notice
of Claim, Loss or Circumstance in the Declarations.
Any Claim arising out of a Loss that is covered under the Breach Response, First Party
Data & Network Loss or eCrime insuring agreements and that is reported to the
Underwriters in conformance with the foregoing will be considered to have been made
during the Policy Period.
Beazley Breach Response Services
The Underwriters' dedicated business unit focused exclusively on helping Insureds
successfully prepare for and respond to actual or suspected Data Breaches and
Security Breaches (the "Beazley Breach Response Services Team") will be available to
F00731
022019 ed. Page 20 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
assist the Named Insured in responding to an actual or suspected Data Breach or
Security Breach. The Beazley Breach Response Services Team will work in
collaboration with the Named Insured to triage and assess the severity of a data breach
incident, while assisting the coordination of the range of resources and services the
Named Insured may need to meet legal requirements and maintain customer
confidence. The Beazley Breach Response Services Team may be reached via email at:
bbr.claims@beazley.com or via a toll-free 24-Hour Hotline: (866)567-8570.
The Named Insured will have access, via the Beazley Breach Response Services Team,
to the Underwriters' network of third party breach response service providers, products
and services to respond to an actual or suspected Data Breach or Security Breach.
Coverage for the costs of products and services provided by any breach response
service provider is subject to the terms and conditions of this Policy.
The Named Insured will also have access to educational and loss control information
and services made available by the Underwriters from time to time and includes access
to beazleyb reach solutions.com, a dedicated portal through which it can access news and
information regarding breach response planning, data and network security threats, best
practices in protecting data and networks, offers from third party service providers, and
related information, tools and services. The Named Insured will also have access to
communications addressing timely topics in data security, loss prevention and other
areas.
Notwithstanding the foregoing, an actual or suspected Data Breach or Security Breach
must be reported to the Underwriters in accordance with the Notice of Claim or Loss
clause in order for such incident to be eligible for coverage under the Breach Response
insuring agreement. Assistance from and access to the Beazley Breach Response
Services Team will terminate after the Policy Aggregate Limit of Liability has been
exhausted, or after deposit of the Policy Aggregate Limit of Liability in a court of
competent jurisdiction.
Notice of Circumstance
With respect to any circumstance that could reasonably be the basis for a Claim, the
Insured may give written notice of such circumstance to the Underwriters through the
contacts listed for Notice of Claim, Loss or Circumstance in the Declarations as soon as
practicable during the Policy Period. Such notice must include:
1. the specific details of the act, error, omission or event that could reasonably be
the basis for a Claim;
2. the injury or damage which may result or has resulted from the circumstance;
and
3. the facts by which the Insured first became aware of the act, error, omission or
event.
Any subsequent Claim made against the Insured arising out of any circumstance
reported to Underwriters in conformance with the foregoing will be considered to have
been made at the time written notice complying with the above requirements was first
given to the Underwriters during the Policy Period.
Defense of Claims
Except with respect to coverage under the Payment Card Liabilities & Costs insuring
agreement, the Underwriters have the right and duty to defend any covered Claim or
F00731
022019 ed. Page 21 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Regulatory Proceeding. Defense counsel will be mutually agreed by the Named
Insured and the Underwriters but, in the absence of such agreement, the Underwriters'
decision will be final.
With respect to the Payment Card Liabilities & Costs insuring agreement, coverage will
be provided on an indemnity basis and legal counsel will be mutually agreed by the
Named Insured and the Underwriters.
The Underwriters will pay actual loss of salary and reasonable expenses resulting from
the attendance by a corporate officer of the Insured Organization at any mediation
meetings, arbitration proceedings, hearings, depositions, or trials relating to the defense
of any Claim, subject to a maximum of USD 2,000 per day and USD 100,000 in the
aggregate, which amounts will be part of and not in addition to the Policy Aggregate
Limit of Liability.
Settlement of Claims
If the Insured refuses to consent to any settlement recommended by the Underwriters
and acceptable to the claimant, the Underwriters' liability for such Claim will not exceed:
1. the amount for which the Claim could have been settled, less the remaining
Retention, plus the Claims Expenses incurred up to the time of such refusal;
plus
2. sixty percent (60%) of any Claims Expenses incurred after the date such
settlement or compromise was recommended to the Insured plus sixty percent
(60%) of any Damages, Penalties and PCI Fines, Expenses and Costs above
the amount for which the Claim could have been settled;
and the Underwriters will have the right to withdraw from the further defense of such
Claim.
The Insured may settle any Claim where the Damages, Penalties, PCI Fines,
Expenses and Costs and Claims Expenses do not exceed 50%of the Retention, provided
that the entire Claim is resolved and the Insured obtains a full release on behalf of all
Insureds from all claimants.
Assistance and Cooperation
The Underwriters will have the right to make any investigation they deem necessary, and the
Insured will cooperate with the Underwriters in all investigations, including investigations
regarding coverage under this Policy and the information and materials provided to the
underwriters in connection with the underwriting and issuance of this Policy. The Insured
will execute or cause to be executed all papers and render all assistance as is requested by
the Underwriters. The Insured agrees not to take any action which in any way increases
the Underwriters' exposure under this Policy. Expenses incurred by the Insured in
assisting and cooperating with the Underwriters do not constitute Claims Expenses
under the Policy.
The Insured will not admit liability, make any payment, assume any obligations, incur any
expense, enter into any settlement, stipulate to any judgment or award or dispose of any
Claim without the written consent of the Underwriters, except as specifically provided in
the Settlement of Claims clause above. Compliance with a Breach Notice Law will not
be considered an admission of liability.
F00731
022019 ed. Page 22 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Subrogation
If any payment is made under this Policy and there is available to the Underwriters any
of the Insured's rights of recovery against any other party, then the Underwriters will
maintain all such rights of recovery. The Insured will do whatever is reasonably
necessary to secure such rights and will not do anything after an incident or event giving
rise to a Claim or Loss to prejudice such rights. If the Insured has waived its right to
subrogate against a third party through written agreement made before an incident or
event giving rise to a Claim or Loss has occurred, then the Underwriters waive their
rights to subrogation against such third party. Any recoveries will be applied first to
subrogation expenses, second to Loss paid by the Underwriters, and lastly to the
Retention. Any additional amounts recovered will be paid to the Named Insured.
Other Insurance
The insurance under this Policy will apply in excess of any other valid and collectible
insurance available to any Insured unless such other insurance is written only as specific
excess insurance over this Policy. Provided, however, this Policy will become primary
and non-contributory insurance as respects any insurance maintained by an Additional
Insured if primary insurance is required by a contract in place between the Additional
Insured and the Insured Organization, but only with respect to any Claim arising solely
from the Media, Tech, Data & Network Liability insuring agreements.
Action Against the Underwriters
No action will lie against the Underwriters or the Underwriters' representatives unless and
until, as a condition precedent thereto, the Insured has fully complied with all provisions,
terms and conditions of this Policy and the amount of the Insured's obligation to pay has
been finally determined either by judgment or award against the Insured after trial,
regulatory proceeding, arbitration or by written agreement of the Insured, the claimant,
and the Underwriters.
No person or organization will have the right under this Policy to join the Underwriters as
a party to an action or other proceeding against the Insured to determine the Insured's
liability, nor will the Underwriters be impleaded by the Insured or the Insured's legal
representative.
The Insured's bankruptcy or insolvency of the Insured's estate will not relieve the
Underwriters of their obligations hereunder.
Entire Agreement
By acceptance of the Policy, all Insureds agree that this Policy embodies all agreements
between the Underwriters and the Insured relating to this Policy. Notice to any agent, or
knowledge possessed by any agent or by any other person, will not effect a waiver or a
change in any part of this Policy or stop the Underwriters from asserting any right under
the terms of this Policy; nor will the terms of this Policy be waived or changed, except by
endorsement issued to form a part of this Policy signed by the Underwriters.
Mergers or Consolidations
If during the Policy Period the Named Insured consolidates or merges with or is
acquired by another entity, or sells more than 50% of its assets to another entity, then
this Policy will continue to remain in effect through the end of the Policy Period, but only
with respect to events, acts or incidents that occur prior to such consolidation, merger or
acquisition. There will be no coverage provided by this Policy for any other Claim or
F00731
022019 ed. Page 23 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Loss unless the Named Insured provides written notice to the Underwriters prior to such
consolidation, merger or acquisition, the Named Insured has agreed to any additional
premium and terms of coverage required by the Underwriters and the Underwriters have
issued an endorsement extending coverage under this Policy.
Assignment
The interest hereunder of any Insured is not assignable. If the Insured dies or is
adjudged incompetent, such insurance will cover the Insured's legal representative as if
such representative were the Insured, in accordance with the terms and conditions of
this Policy.
Cancellation
This Policy may be cancelled by the Named Insured by giving written notice to the
Underwriters through the entity listed for Administrative Notice in the Declarations stating
when the cancellation will be effective.
This Policy may be cancelled by the Underwriters by mailing to the Named Insured at
the address listed in the Declarations written notice stating when such cancellation will be
effective. Such date of cancellation will not be less than 60 days (or 10 days for
cancellation due to non-payment of premium) after the date of notice.
If this Policy is canceled in accordance with the paragraphs above, the earned premium
will be computed pro rata; but the premium will be deemed fully earned if any Claim, or
any circumstance that could reasonably be the basis for a Claim or Loss, is reported to
the Underwriters on or before the date of cancellation. Payment or tender of unearned
premium is not a condition of cancellation.
Singular Form of a Word
Whenever the singular form of a word is used herein, the same will include the plural
when required by context.
Headings
The titles of paragraphs, clauses, provisions or endorsements of or to this Policy are
intended solely for convenience and reference, and are not deemed in any way to limit or
expand the provisions to which they relate and are not part of the Policy.
Representation by the Insured
All Insureds agree that the statements contained the information and materials provided
to the Underwriters in connection with the underwriting and issuance of this Policy are
true, accurate and are not misleading, and that the Underwriters issued this Policy, and
assume the risks hereunder, in reliance upon the truth thereof.
Named Insured as Agent
The Named Insured will be considered the agent of all Insureds, and will act on behalf
of all Insureds with respect to the giving of or receipt of all notices pertaining to this
Policy, and the acceptance of any endorsements to this Policy. The Named Insured is
responsible for the payment of all premiums and Retentions and for receiving any return
premiums.
F00731
022019 ed. Page 24 of 24
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Have a complaint or need help?
If you have a problem with a claim or your premium, call your insurance company or HMO first.
If you can't work out the issue, the Texas Department of Insurance may be able to help.
Even if you file a complaint with the Texas Department of Insurance, you should also file a
complaint or appeal through your insurance company or HMO. If you don't, you may lose your
right to appeal.
Beazley USA Services, Inc. (on behalf of one or more Beazley Group insurers)
To get information or file a complaint with your insurance company or HMO:
Call: Compliance Department at 1-860-677-3700
Toll Free: 1-866-623-2953
Online: www.beazley.com
Email: us.complaints(a)beazley.com
Mail: 30 Batterson Park Road
Farmington, CT 06032
The Texas Department of Insurance
To get help with an insurance question or file a complaint with the state:
Call with a question: 1-800-252-3439
File a complaint: www.tdi.texas.gov
Email: ConsumerProtection(a�tdi.texas.gov
Mail: MC 111-1A
P.O. Box 149091
Austin, TX 78714-9091
A01110TX Page 1 of 2
052020 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
jiene una queja o necesita ayuda?
Si tiene un problema con una reclamacion o con su prima de seguro, Ilame primero a su
compania de seguros o HMO. Si no puede resolver el problema, es posible que el
Departamento de Seguros de Texas (Texas Department of Insurance, por su nombre en ingles)
pueda ayudar.
Aun si usted presenta una queja ante el Departamento de Seguros de Texas, tambien debe
presentar una queja a traves del proceso de quejas o de apelaciones de su compania de
seguros o HMO. Si no to hace, podria perder su derecho para apelar.
Beazley USA Services, Inc. (on behalf of one or more Beazley Group insurers)
Para obtener informacion o para presenter una queja ante su compania de seguros o HMO:
Llame a: Compliance Departmental 1-860-677-3700
Telefono gratuito: 1-866-623-2953
En linea: www.beazleV.com
Correo electronico: us.complaints(d-)beazley.com
Direccion postal: 30 Batterson Park Road
Farmington, CT 06032
El Departamento de Seguros de Texas
Para obtener ayuda con una pregunta relacionada con los seguros o para presentar una queja
ante el estado:
Llame con sus preguntas al: 1-800-252-3439
Presente una queja en: www.tdi.texas.gov
Correo electronico: ConsumerProtection(a tdi.texas.gov
Direccion postal: MC 111-1A
P.O. Box 149091
Austin, TX 78714-9091
A01110TX Page 2 of 2
052020 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
NOTIFICATION OF THE AVAILABILITY OF LOSS CONTROL INFORMATION/SERVICES -TEXAS
Beazley Insurance Company, Inc. is committed to providing loss control information and services to its
Texas policyholders at no charge in an effort to prevent and reduce potential claims.
To obtain information or to request services, you may call:
Jennifer Englund
Compliance
1-866-623-2953
You may also request this information by writing to:
Beazley Insurance Company, Inc.
30 Batterson Park Road
Farmington, Connecticut 06032
Attn: Jennifer Englund
Compliance
A01150TX Page 1 of 1
032014 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
TEXAS AMENDATORY ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
1. The NOTICE at the top of the first page above the INSURING AGREEMENTS section is amended to
add ", Automatic Extension Period" before the words"or Optional Extension Period (if applicable)".
2. The following is added to the Settlement of Claims provision of the GENERAL CONDITIONS section:
The Underwriters shall provide written notice to the Named Insured of an initial offer to settle or
compromise a Claim against an Insured, not less than ten (10) days after the date on which the
offer to settle or compromise is made, unless the Named Insured advised the Underwriters of such
initial offer to settle or compromise the Claim. The Underwriters shall also provide written notice to
the Named Insured of the settlement of a Claim against an Insured, not less than thirty (30) days
after the settlement.
3. The phrase "Optional Extension Period", wherever it appears, shall be deemed to include "Automatic
Extension Period".
4. The OPTIONAL EXTENSION PERIOD section is deleted in its entirety and replaced with the
following:
AUTOMATIC AND OPTIONAL EXTENSION PERIODS
The Named Insured shall have an automatic thirty (30) day extension of the coverage granted
by this Policy following the effective date of cancellation or nonrenewal, but only with respect to
any act, error or omission committed on or after the Retroactive Date and before the effective
date of cancellation or nonrenewal. This period shall be referred to herein as the "Automatic
Extension Period".
If the Underwriters or the Named Insured cancels or nonrenews this Policy for any reason except
the non-payment of premium, then the Named Insured shall have the right, upon payment of an
additional premium calculated at that percentage shown in the Optional Extension Premium
provision of the Declarations of the total premium for this Policy, to an extension of the coverage
granted by this Policy with respect to any Claim first made against any Insured and reported in
writing to the Underwriters during the period of time set forth in the Optional Extension Period
provision of the Declarations after the end of the Automatic Extension Period, but only with
respect to any act, error or omission committed on or after the Retroactive Date and before the
effective date of cancellation or nonrenewal. The Optional Extension Period offered by the
Underwriters shall be at least one year in length.
The right to purchase the Optional Extension Period shall terminate unless written notice together
with full payment of the premium for the Optional Extension Period is given to the Underwriters
within thirty (30) days after the effective date of cancellation or nonrenewal. If such notice and
premium payment is not so given to the Underwriters, there shall be no right to purchase the
Optional Extension Period.
In the event of the purchase of the Optional Extension Period, the entire premium for the Optional
Extension Period shall be deemed earned at its commencement.
A01801 TX Page 1 of 3
092019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
The Automatic Extension Period and the purchase of the Optional Extension Period shall not in
any way increase the Limit of Liability of the Underwriters.
5. The title of the Cancellation provision in the GENERAL CONDITIONS section is changed to
Cancel lation/Nonrenewal.
6. The second paragraph of the Cancellation/Nonrenewal provision in the GENERAL CONDITIONS
section is deleted in its entirety and replaced by the following:
If this Policy has been in effect for sixty(60) days or less and is not a renewal Policy, the Underwriters
may cancel this Policy for any reason.
If this Policy has been in effect for more than sixty (60) days, the Underwriters may only cancel this
Policy for any of the following reasons:
1. fraud in obtaining coverage;
2. failure to pay premiums when due;
3. increase in hazard within the control of the Insured that would produce a rate increase;
4. loss of the Underwriters' reinsurance covering all or part of the risk covered by the Policy;
or
5. the Underwriters are placed in supervision, conservatorship, or receivership and the
cancellation is approved or directed by the supervisor, conservator, or receiver.
The Underwriters may cancel this Policy by mailing or delivering to the Named Insured written notice
stating when, not less than ten (10) days thereafter, such cancellation shall be effective. The notice
of cancellation shall state the reason for cancellation. The mailing of such notice shall be sufficient
notice and the effective date of cancellation stated in the notice shall become the end of the Policy
Period. Delivery of such written notice by the Underwriters shall be equivalent to mailing. The
Underwriters shall not cancel this Policy based solely on the fact that the Insured is an elected
official.
7. The phrase "; but the premium will be deemed fully earned if any Claim, or any circumstance that
could reasonably be the basis for a Claim or Loss, is reported to the Underwriters on or before the
date of cancellation" in the third paragraph of the Cancel lation/Nonrenewal provision in the
GENERAL CONDITIONS section is deleted.
8. The following is added to the Cancellation/Nonrenewal provision in the GENERAL CONDITIONS
section:
If the Underwriters decide not to renew this Policy, the Underwriters shall mail or deliver written
notice to the Named Insured at the address shown in the Declarations at least sixty (60) days
before the end of the Policy Period. The notice of nonrenewal shall state the reason for
nonrenewal. If notice of nonrenewal is delivered or mailed later than the 60th day before the date
the Policy expires, the Policy's coverage shall remain in effect until the 61st day after the date on
which the notice is delivered or mailed. Earned premium for any period of coverage that extends
beyond the Policy's expiration date shall be computed pro rata based on the Policy's current rate.
If this Policy is so extended, such period of extended coverage shall be part of and not in addition
to the Policy Period. The Underwriters shall not refuse to renew this Policy based solely on the
fact that the Insured is an elected official.
The regulatory requirements set forth in this Amendatory Endorsement shall supersede and take
precedence over any provisions of this Policy or any endorsement to this Policy, whenever added, that
A01801 TX Page 2 of 3
092019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
are inconsistent with or contrary to the provisions of this Amendatory Endorsement, unless such Policy or
endorsement provisions comply with the applicable insurance laws of this state.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
A01801 TX Page 3 of 3
092019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
NUCLEAR EXCLUSION
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that this Policy
does not apply:
I. Under any Liability Coverage, to injury, sickness, disease, death or destruction:
(a) with respect to which an insured under the Policy is also an insured under a nuclear energy
liability policy issued by Nuclear Energy Liability Insurance Association, Mutual Atomic
Energy Liability Underwriters or Nuclear Insurance Association of Canada, or would be an
insured under any such policy but for its termination upon exhaustion of its limit of liability;
or
(b) resulting from the hazardous properties of nuclear material and with respect to which (1)any
person or organization is required to maintain financial protection pursuant to the Atomic
Energy Act of 1954, or any law amendatory thereof, or(2)the insured is, or had this Policy
not been issued would be, entitled to indemnity from the United States of America, or any
agency thereof, under any agreement entered into by the United States of America, or any
agency thereof, with any person or organization.
II. Under any Medical Payments Coverage, or under any Supplementary Payments Provision relating to
immediate medical or surgical relief, to expenses incurred with respect to bodily injury, sickness,
disease or death resulting from the hazardous properties of nuclear material and arising out of the
operation of a nuclear facility by any person or organization.
III. Under any Liability Coverage, to injury, sickness, disease, death or destruction resulting from the
hazardous properties of nuclear material, if:
(a) the nuclear material (1) is at any nuclear facility owned by, or operated by or on behalf of, an
insured or(2) has been discharged or dispersed therefrom;
(b) the nuclear material is contained in spent fuel or waste at any time possessed, handled,
used, processed, stored, transported or disposed of by or on behalf of an insured; or
(c) the injury, sickness, disease, death or destruction arises out of the furnishing by an insured
of services, materials, parts or equipment in connection with the planning, construction,
maintenance, operation or use of any nuclear facility, but if such facility is located within the
United States of America, its territories or possessions or Canada, this exclusion (c) applies
only to injury to or destruction of property at such nuclear facility.
IV. As used in this endorsement:
BICMU05090406 Page 1 of 2
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
"hazardous properties" include radioactive, toxic or explosive properties; "nuclear material" means
source material, special nuclear material or by-product material; "source material", "special nuclear
material", and "by-product material" have the meanings given them in the Atomic Energy Act 1954
or in any law amendatory thereof; "spent fuel" means any fuel element or fuel component, solid or
liquid, which has been used or exposed to radiation in a nuclear reactor; "waste" means any waste
material (1) containing by-product material and (2) resulting from the operation by any person or
organization of any nuclear facility included within the definition of nuclear facility under paragraph
(a) or (b) thereof; "nuclear facility" means:
(a) any nuclear reactor,
(b) any equipment or device designed or used for(1) separating the isotopes of uranium or
plutonium, (2) processing or utilizing spent fuel, or(3) handling, processing or packaging
waste,
(c) any equipment or device used for the processing, fabricating or alloying of special nuclear
material if at any time the total amount of such material in the custody of the insured at the
premises where such equipment or device is located consists of or contains more than 25
grams of plutonium or uranium 233 or any combination thereof, or more than 250 grams of
uranium 235,
(d) any structure, basin, excavation, premises or place prepared or used for the storage or
disposal of waste,
and includes the site on which any of the foregoing is located, all operations conducted on such
site and all premises used for such operations; "nuclear reactor" means any apparatus designed or
used to sustain nuclear fission in a self-supporting chain reaction or to contain a critical mass of
fissionable material. With respect to injury to or destruction of property, the word "injury" or
"destruction" includes all forms of radioactive contamination of property.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
BICMU05090406 Page 2 of 2
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
SANCTION LIMITATION AND EXCLUSION CLAUSE
This endorsement modifies insurance provided under the following:
Beazley MediaTech
No (re)insurer shall be deemed to provide cover and no (re)insurer shall be liable to pay any claim or
provide any benefit hereunder to the extent that the provision of such cover, payment of such claim or
provision of such benefit would expose that (re)insurer to any sanction, prohibition or restriction under
United Nations resolutions or the trade or economic sanctions, law or regulations of the European Union,
United Kingdom or United States of America.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E02804 Page 1 of 1
032011 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
WAR AND CIVIL WAR EXCLUSION
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that
EXCLUSIONS is amended to include:
War and Civil War
or resulting from, directly or indirectly occasioned by, happening through or in consequence of:
war, invasion, acts of foreign enemies, hostilities (whether war be declared or not), civil war,
rebellion, revolution, insurrection, military or usurped power or confiscation or nationalization or
requisition or destruction of or damage to property by or under the order of any government or
public or local authority; provided, that this exclusion will not apply to Cyber Terrorism.
For purposes of this exclusion, "Cyber Terrorism" means the premeditated use of disruptive
activities, or threat to use disruptive activities, against a computer system or network with the
intention to cause harm, further social, ideological, religious, political or similar objectives, or to
intimidate any person(s) in furtherance of such objectives.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12254 Pagel of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
ASBESTOS, POLLUTION, AND CONTAMINATION EXCLUSION ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that the
coverage under this Policy will not apply to any Loss arising out of either in whole or in part, directly or
indirectly arising out of or resulting from or in consequence of, or in any way involving:
1. asbestos, or any materials containing asbestos in whatever form or quantity;
2. the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of
any fungi, molds, spores or mycotoxins of any kind; any action taken by any party in response to
the actual, potential, alleged or threatened formation, growth, presence, release or dispersal of
fungi, molds, spores or mycotoxins of any kind, such action to include investigating, testing for,
detection of, monitoring of, treating, remediating or removing such fungi, molds, spores or
mycotoxins; and any governmental or regulatory order, requirement, directive, mandate or
decree that any party take action in response to the actual, potential, alleged or threatened
formation, growth, presence, release or dispersal of fungi, molds, spores or mycotoxins of any
kind, such action to include investigating, testing for, detection of, monitoring of, treating,
remediating or removing such fungi, molds, spores or mycotoxins;
The Underwriters will have no duty or obligation to defend any Insured with respect to any
Claim or governmental or regulatory order, requirement, directive, mandate or decree which
either in whole or in part, directly or indirectly, arises out of or results from or in consequence of,
or in any way involves the actual, potential, alleged or threatened formation, growth, presence,
release or dispersal of any fungi, molds, spores or mycotoxins of any kind;
3. the existence, emission or discharge of any electromagnetic field, electromagnetic radiation or
electromagnetism that actually or allegedly affects the health, safety or condition of any person
or the environment, or that affects the value, marketability, condition or use of any property; or
4. the actual, alleged or threatened discharge, dispersal, release or escape of Pollutants; or any
governmental,judicial or regulatory directive or request that the Insured or anyone acting under
the direction or control of the Insured test for, monitor, clean up, remove, contain, treat, detoxify
or neutralize Pollutants. Pollutants means any solid, liquid, gaseous or thermal irritant or
contaminant including gas, acids, alkalis, chemicals, heat, smoke, vapor, soot, fumes or waste.
Waste includes but is not limited to materials to be recycled, reconditioned or reclaimed.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12287 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
AGGREGATE/MAINTENANCE RETENTION
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The maximum aggregate Retention for all Claims made during any Policy Year under this Policy
shall be $15,000 provided, that the each Claim Retention set forth in item 3. below shall not be
subject to any aggregate Retention.
2. For purposes of this endorsement, the term "Policy Year" means each 365 day period beginning with
the Inception Date of the Policy Period and each such succeeding Policy Period, if any.
3. With respect to any Claim made in any Policy Year after the maximum aggregate Retention is
reached for that Policy Year, the each Claim Retention shall be $0.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12228 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
AMEND DEFINITION OF FRAUDULENT INSTRUCTION
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that the
definition of Fraudulent Instruction is deleted in its entirety and replaced with the following:
Fraudulent Instruction means the transfer, payment or delivery of Money or Securities by an
Insured as a result of fraudulent written, electronic, telegraphic, cable, teletype or telephone
instructions provided by a third party, that is intended to mislead an Insured through the
misrepresentation of a material fact which is relied upon in good faith by such Insured.
Fraudulent Instruction will not include loss arising out of:
1. any actual or alleged use of credit, debit, charge, access, convenience, customer
identification or other cards;
2. any transfer involving a third party who is not a natural person Insured, but had
authorized access to the Insured's authentication mechanism;
3. the processing of, or the failure to process, credit, check, debit, personal identification
number debit, electronic benefit transfers or mobile payments for merchant accounts;
4. accounting or arithmetical errors or omissions, or the failure, malfunction, inadequacy
or illegitimacy of any product or service;
5. any liability to any third party, or any indirect or consequential loss of any kind;
6. any legal costs or legal expenses; or
7. proving or establishing the existence of Fraudulent Instruction.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12266 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
GDPR CYBER ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that the
definition of Data & Network Wrongful Act is amended to include the following:
5. non-compliance with the following obligations under the EU General Data Protection Regulation:
(i) Article 5.1(f), also known as the Security Principle;
(ii) Article 32, Security of Processing;
(iii) Article 33, Communication of a Personal Data Breach to the Supervisory Authority; or
(iv) Article 34, Communication of a Personal Data Breach to the Data Subject.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12269 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
COMPUTER HARDWARE REPLACEMENT COST
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The definition of Extra Expense is deleted in its entirety and replaced with the following:
Extra Expense means reasonable and necessary expenses incurred by the Insured
Organization during the Period of Restoration to minimize, reduce or avoid Income Loss,
over and above those expenses the Insured Organization would have incurred had no
Security Breach, System Failure, Dependent Security Breach or Dependent System
Failure occurred; and includes reasonable and necessary expenses incurred by the Insured
Organization to replace computers or any associated devices or equipment operated by, and
either owned by or leased to, the Insured Organization that are unable to function as intended
due to corruption or destruction of software or firmware directly resulting from a Security
Breach, provided however that the maximum sublimit applicable to Extra Expense incurred to
replace such devices or equipment is USD $100,000.
2. Part 2. of the Bodily Injury or Property Damage exclusion is deleted in its entirety and
replaced with the following:
2. physical injury to or destruction of any tangible property, including the loss of use
thereof; but this will not apply to the loss of use of computers or any associated devices
or equipment operated by, and either owned by or leased to, the Insured Organization
that are unable to function as intended due to corruption or destruction of software or
firmware directly resulting from a Security Breach. Electronic data shall not be
considered tangible property;
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12289 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
CONTINGENT BODILY INJURY WITH SUBLIMIT ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The Bodily Injury or Property Damage exclusion is deleted in its entirety and replaced with the
following:
Bodily Injury or Property Damage
1. Bodily Injury; provided, this exclusion shall not apply to any Claim for Contingent
Bodily Injury; and
2. physical injury to or destruction of any tangible property, including the loss of use
thereof; but electronic data will not be considered tangible property;
2. DEFINITIONS is amended by the addition of:
Bodily Injury means physical injury, sickness, disease or death of any person, including any
mental anguish or emotional distress that results from such physical injury, sickness, disease or
death.
Contingent Bodily Injury means those Claims wherein the Damages sought by the claimant
are for Bodily Injury which arise solely out of a Security Breach affecting the Insured
Organization's Computer Systems which is otherwise covered under the terms and conditions
of this Policy; but not if the Insured's own act, error or omission is the direct immediate cause of
such Claim for Bodily Injury. Furthermore, this extension of coverage applies only if such
Claim for Bodily Injury is not covered under any other policy of insurance.
3. The Underwriter's aggregate limit of liability for all Damages resulting from all Claims covered
under this Endorsement, made against any Insured(s) based upon, arising out of, directly or
indirectly resulting from or in consequence of, or in any way involving any Contingent Bodily
Injury shall be $250,000, which amount shall be part of and not in addition to the Policy
Aggregate Limit of Liability.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12290 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
INVOICE MANIPULATION COVERAGE
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The aggregate sublimit applicable to all loss under this endorsement is USD $100,000.
2. The Retention applicable to each incident, event, or related incidents or events, giving rise to an
obligation to pay loss under this endorsement shall be USD $5,000.
3. INSURING AGREEMENTS is amended to include:
Invoice Manipulation
To indemnify the Insured Organization for Direct Net Loss resulting directly from the
Insured Organization's inability to collect Payment for any goods, products or services
after such goods, products or services have been transferred to a third party, as a result
of Invoice Manipulation that the Insured first discovers during the Policy Period:
4. DEFINITIONS is amended to include:
Direct Net Loss means the direct net cost to the Insured Organization to provide goods,
products or services to a third party. Direct Net Loss will not include any profit to the Insured
Organization as a result of providing such goods, products or services.
Invoice Manipulation means the release or distribution of any fraudulent invoice or fraudulent
payment instruction to a third party as a direct result of aSecurity Breach or a Data Breach.
Payment means currency, coins or bank notes in current use and having a face value.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12293 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
Post Breach Remedial Services Endorsement
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that, following a
covered Data Breach or Security Breach involving the actual Unauthorized Access or Use of the
Insured Organization's Computer Systems for which the Insured Organization has utilized services
exclusively from Beazley Service Providers, the Insured Organization will be eligible to receive Post
Breach Remedial Services.
Post Breach Remedial Services means up to 100 hours per Policy Period of post-breach computer
security consultation and remedial services to be provided by Lodestone Security ("Lodestone"). Such
services will be provided at the Insured Organization's request as per the description of services
attached to this endorsement. Post Breach Remedial Services will be considered Breach Response
Costs, and will be available in response to incidents in which forensic costs covered under parts 2. and 3.
of the definition of Breach Response Costs have been incurred, subject to the applicable Retention.
Post Breach Remedial Services will not include any costs to purchase or upgrade any hardware or
software.
To access the Post Breach Remedial Services, the Insured Organization must:
1. notify the Beazley Breach Response Services Team via email at:
bbr.claims(@beazley.com or via a toll-free 24-Hour Hotline: (866) 567-8570 following any
actual or reasonably suspected Unauthorized Access or Use of the Insured
Organization's Computer Systems so that the Beazley Breach Response Services
Team can work with the Insured Organization to coordinate the provision of services
from Beazley Service Providers;
2. notify the Underwriters that they desire to receive such services; and
3. enter into an engagement agreement with Lodestone to receive such service,
within sixty (60) days following a determination of the actual Unauthorized Access or Use of the Insured
Organization's Computer Systems,
For purpose of this Endorsement, "Beazley Service Providers" means the Underwriters' network of third
party breach response service providers listed at www.beazley.com/cyberservices that are to be utilized
exclusively in response to incidents in which forensic costs covered under parts 2. and 3. of the definition
of Breach Response Costs have been/will be incurred, subject to the applicable Retention.
All other terms and conditions of this Policy remain unchanged.
i
Authorized Representative
E12716 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
CRISIS MANAGEMENT EXPENSE COVERAGE
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The Limits listed in the Declarations under COVERAGE SCHEDULE are amended to include:
Crisis Management Expenses: $1,000,000
2. INSURING AGREEMENTS is amended to include the following:
To indemnify the Named Insured for 100% of the costs of a public relations consultancy incurred
by the Insured Organization with Underwriters' prior written consent, for the purpose of averting
or mitigating material damage to the Insured Organization's reputation that results or reasonably
will result from a Claim covered under by the Policy and publicized through any
media channel ("Crisis Management Expenses"); provided, this coverage shall only apply when
covered Damages other than (crisis management expenses) exceeds the applicable Retention.
3. The definition of Damages is amended to include Crisis Management Expenses.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12864 Pagel of 1
042019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
CRYPTOJACKING ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The aggregate sublimit applicable to all loss under this endorsement is USD $100,000.
2 The Retention applicable to each incident, event, or related incidents or events, giving rise to an
obligation to pay loss under this endorsement shall be USD $5,000.
3. INSURING AGREEMENTS is amended to include:
Cryptojacking
To indemnify the Insured Organization for any direct financial loss sustained resulting
from Cryptojacking that the Insured first discovers during the Policy Period.
4. DEFINITIONS is amended to include:
Cryptojacking means the Unauthorized Access or Use of Computer Systems to mine for
Digital Currency that directly results in additional costs incurred by the Insured Organization
for electricity, natural gas, oil, or internet(the "Utilities"); provided, however, that such additional
costs for the Utilities are:
1. incurred pursuant to a written contract between the Insured Organization and
the respective utility provider, which was executed before the Cryptojacking
first occurred;
2. billed to the Insured Organization by statements issued by the respective utility
provider, which include usage or consumption information;
3. not charged to the Insured Organization at a flat fee that does not scale with
the rate or use of the respective utility; and
4. incurred pursuant to statements issued by the respective utility provider and due
for payment during the Policy Period.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12972 Page 1 of 1
052019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
REPUTATION LOSS
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. Limit listed in the Declarations under COVERAGE SCHEDULE is amended to include:
Reputation Loss: USD $1,000,000
2. Retention listed in the Declarations underCOVERAGE SCHEDULE is amended to include:
Each incident giving rise to Reputation Loss: USD $5,000
3. INSURING AGREEMENTS is amended by the addition of:
Reputation Loss
To indemnify the Insured Organization for Reputation Loss that the Insured
Organization sustains solely as a result of an Adverse Media Event that occurs during the
Policy Period, concerning:
1. a Data Breach, Security Breach, or Extortion Threat that the Insured first
discovers during the Policy Period; or
2. if this policy is a Renewal, a Data Breach, Security Breach, or Extortion Threat
that the Insured first discovers during the last 90 days of the prior policy period.
4. DEFINITIONS is amended to include:
Adverse Media Event means:
1. publication by a third party via any medium, including but not limited to television,
print, radio, electronic, or digital form of previously non-public information specifically
concerning a Data Breach, Security Breach, or Extortion Threat; or
2. notification of individuals pursuant to part 4. of the Breach Response Costs
definition.
Multiple Adverse Media Events arising from the same or a series of related, repeated or
continuing Data Breaches, Security Breaches, or Extortion Threats, shall be considered
a single Adverse Media Event, and shall be deemed to occur at the time of the first such
Adverse Media Event.
Claims Preparation Costs means reasonable and necessary costs that the Named Insured incurs
to contract with a third party to prepare a proof of loss demonstrating Reputational Loss.
E13040 Page 1 of 3
062019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Protection Period means the period beginning on the date the Adverse Media Event occurs,
and ends after the earlier of:
1. 180 days; or
2. the date that gross revenues are restored to the level they would have been but
for the Adverse Media Event.
Renewal means an insurance policy issued by the Underwriters to the Named Insured for the
policy period immediately preceding this Policy Period that provides coverage for a Data
Breach, Security Breach, or Extortion Threat otherwise covered under this Policy.
Reputation Loss means:
1. the net profit or loss before interest and tax that the Insured Organization would
have earned during the Protection Period but for an Adverse Media Event; and
2. continuing normal operating expenses incurred by the Insured Organization
(including payroll), but only to the extent that such operating expenses must
necessarily continue during the Protection Period.
When calculating any Reputation Loss, due consideration will be given to any amounts
made up during, or within a reasonable time after the end of, the Protection Period.
Reputation Loss will not mean and no coverage will be available under this
endorsement for any of the following:
(i) loss arising out of any liability to any third party;
(ii) legal costs or legal expenses of any type;
(iii) loss incurred as a result of unfavorable business conditions;
(iv) loss of market or any other consequential loss;
(v) Breach Response Costs; or
(vi) Cyber Extortion Loss;
There will be no coverage available under this endorsement if there is an actual
interruption of the Insured Organization's business operations for any period of time.
5. Limits of Liability under LIMIT OF LIABILITY AND COVERAGE is amended to include:
Reputational Loss and Claims Preparation Costs covered under this Policy arising from an
Adverse Media Event concerning any Data Breach, Security Breach, or Extortion Threat
(including a series of related, repeated or continuing Data Breaches, Security Breaches, or
Extortion Threats) first discovered during the last 90 days of the prior policy period, will be
considered to have been noticed to the Underwriters during the prior policy period and will be
subject to the Policy Aggregate Limit of Liability of the prior policy period. Under such
circumstances, if the Policy Aggregate Limit of Liability of the prior policy period is exhausted
due to payments made under the prior policy, the Underwriter's obligation to pay Reputational
Loss or Claims Preparation Costs under this Policy shall be completely fulfilled and
extinguished.
E13040 Page 2 of 3
062019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
6. Notice of Claim or Loss under GENERAL CONDITIONS is amended to include:
With respect to Reputation Loss, the Named Insured must notify the Underwriters through the
contacts listed for Notice of Claim, Loss or Circumstance in the Declarations as soon as
practicable after discovery of the circumstance, incident or event giving rise to such loss.
All Reputation Loss must be reported, and all proofs of loss must be provided, to the
Underwriters no later than four (4) months after the end of the Protection Period.
7. This Policy will cover up to USD 50,000 of Claims Preparation Costs in excess of the Retention
stated in Section 2. of this endorsement.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E13040 Page 3 of 3
062019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
STATE CONSUMER PRIVACY STATUTES ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that:
1. The Policy is amended to include the following insuring agreement:
State Consumer Privacy Statutes
To pay Penalties and Claims Expenses which the Insured is legally obligated to pay because of
any Regulatory Proceeding first made against any Insured during the Policy Period for a
violation of the California Consumer Privacy Act or any similar state statutes or state regulations
specifically governing the Insured Organization's collection, use, disclosure, sale, processing,
profiling, acquisition, sharing, maintenance, retention or storage of or provision of access to
personal information or personal data as defined under the California Consumer Privacy Act or
similar state statutes or state regulations.
2. The definition of Claim is amended to include institution of a Regulatory Proceeding against any
Insured under the State Consumer Privacy Statutes insuring agreement for a violation of the
California Consumer Privacy Act or any similar state statutes or state regulations specifically
governing the Insured Organization's collection, use, disclosure, sale, processing, profiling,
acquisition, sharing, maintenance, retention or storage of or provision of access to personal
information or personal data as defined under the California Consumer Privacy Act or similar
state statutes or state regulations.
3. The Governmental Actions exclusion will not apply to the State Consumer Privacy Statutes
insuring agreement.
4. Solely with respect to the State Consumer Privacy Statutes insuring agreement, the Deceptive
Business Practices, Antitrust & Consumer Protection exclusion is deleted in its entirety and
replaced with the following:
Deceptive Business Practices and Consumer Protection
any actual or alleged false, deceptive or unfair trade practices, unfair competition, or violation
of consumer protection law; but this exclusion will not apply to coverage under the State
Consumer Privacy Statutes insuring agreement, provided no member of the Control Group
participated in or colluded in the activities or incidents giving rise to coverage under such
insuring agreement;
Antitrust
any actual or alleged antitrust violation, restraint of trade, false, deceptive or misleading
advertising, violation of the Sherman Antitrust Act, the Clayton Act, or the Robinson-Patman
Act, or inaccurate cost estimates or failure of goods or services to conform with any
represented quality or performance;
E13373 Pagel of 2
092019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
All other terms and conditions of this Policy remain unchanged.
t
Authorized Representative
E13373 Page 2 of 2
092019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
EMPLOYEE DEVICE ENDORSEMENT
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that the
definition of Computer Systems is amended to include computers, any software residing on such
computers and any associated devices or equipment (including but not limited to wireless or mobile
devices), operated by any person listed in parts 2., 3. or 4. of the Insured definition, but only for work
done while acting within the scope of his or her employment and related to the conduct of the Insured
Organization's business.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E13916
052020 ed. Page 1 of 1
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Effective date of this Endorsement: 03-Jul-2021
This Endorsement is attached to and forms a part of Policy Number: VG00003589AB
Beazley Insurance Company, Inc.referred to in this endorsement as either the "Insurer" or the "Underwriters"
VOLUNTARY SHUTDOWN COVERAGE
This endorsement modifies insurance provided under the following:
Beazley MediaTech
In consideration of the premium charged for the Policy, it is hereby understood and agreed that the
definition of Security Breach is deleted in its entirety and replaced with the following:
Security Breach means:
1. A failure of computer security to prevent:
(i) Unauthorized Access or Use of Computer Systems, including Unauthorized Access
or Use resulting from the theft of a password from a Computer System or from any
Insured;
(ii) a denial of service attack affecting Computer Systems;
(iii) with respect to coverage under parts 3. and 4. of the Media, Tech, Data & Network
Liability insuring agreement, the Regulatory Defense & Penalties insuring agreement,
and the Payment Card Liabilities & Costs insuring agreement, a denial of service attack
affecting computer systems that are not owned, operated or controlled by an Insured; or
(iv) infection of Computer Systems by malicious code or transmission of malicious code
from Computer Systems; or
2. Solely with respect to the Business Interruption insuring agreement:
(i) the voluntary and intentional shutdown of Computer Systems by the Insured
Organization, with the Underwriters' prior consent, but only to the extent necessary to
limit the Loss resulting from a situation described in 1.(i)or 1.(iv) above; or
(ii) the intentional shutdown of Computer Systems by the Insured Organization as
expressly required by any federal, state, local or foreign governmental entity in such
entity's regulatory or official capacity resulting from a situation described in 1.(i) or 1.(iv)
above.
All other terms and conditions of this Policy remain unchanged.
Authorized Representative
E12300 Page 1 of 1
022019 ed.
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Attachment D-DigitalLearn-Building Your Own DigitalLearn Site Handout 2021
Pubt'IcLibrary
ASSOC IATIO N
Building Your Own DigitalLearn Site:
Next Steps for Interested Libraries
OLDIGITALLEARN .ORG
is 6 A PLA INITIATIVE
CONTACT INFORMATION
Scott G.Allen, MS, Deputy Director
Public Library Association
225 S. Michigan Avenue, Suite 1300
Chicago, IL 60611
312.280.5858 or sallen@ala.org
1
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
History of DigitalLearn
IMLS grant to develop and launch website
`0 Website and first Learn courses launched
Promotion,development of Teach community
--]New funding partners and new features
'DIGITAL ORG
The need for increased digital literacy skills in the community, and the potential for public
libraries to help communities in this area, led PLA to develop Digital Learn.org.
PLA was awarded a two-year grant from the Institute of Museum and Library Services in the fall
of 2012 to develop DigitalLearn.org. We hired Anneal Inc. out of Denver, Colorado to develop
the strategy and manage the technology, and Kixal, a training and instructional design firm, to
develop the courses. And of course, we consulted our public library members about what they
wanted to see in the product— not just in terms of topics, but in terms of education and literacy
level of the learner, length of the courses, and other features that would make sure it met the
public library's needs. With so many digital literacy training resources out there, we wanted to
make sure our product worked best for public libraries and their patrons needing help.
The website was launched in summer 2013, featuring what was the 14 core courses under the
banner "Learn" In 2014, we added the "Teach" section, which is a community of practice for
digital literacy trainers and others teaching computer skills to share resources.
As DigitalLearn was developed, we've had a
Digital Learn.org Partners number of partners. Core funding from IMLS
helped us develop the program, and the Chief
O PublitLibrary
.;:;;..t,MuseumINSTITUTE'
s dLibrary
ASSOCIATION SERVICES Officers of State Library Agencies and the ALA
Office for Information Technology Policy were
C00A cU t collaborators in its initial development. More
recently, the ALA Office for Diversity, Literacy
ALA Office for Diversity, and Outreach Services is supporting
Literacy and Outreach
Services development of new courses and other
n n_ enhancements, and we are collaborating with
the Chicago Public Library to add new and
exciting features.
2
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9O36E703739
These are over 20 modules ranging from 6 to
Digital Learn.org Content 22 minutes each. PLA intentionally started with
very basic, critical skills. We know these are
Why Use a Computer? Intro to Microsoft Word
Getting Started on the Creating Resumes entry points for using a computer, and once
Computer Online Job Searching these skills are established, it's easier for you
Using a PC(Windows 7) Online Scams
to help your patrons do what they really need
Using PC(Windows 10) Internet Privacy
Using A Mac(OS X) Cloud Storage to do with computers and the Internet.
Basic Search Intro to Facebook
Navigating a Website Buying a Plane Ticket
Accounts and Passwords Intro toSkype We intentionally kept the length of each lesson
Intro to Email Online Scams short based on what we knew learners needed
Intro to Email(Part 2) 111111DIGITALLEARN.ORG and based on feedback of what worked best
.• q PLA INITIATIVE
for public libraries. We also wrote every course
at the 4th grade reading level, with a few exceptions, since some computer terms do not go
below about the 6th grade reading level. The courses are also mostly mobile-device friendly,
although there are some lessons (for instance as you see on the screen, using the mouse) that
do not translate to mobile devices.
.NIGITALLEARN.ORG 2. I'm Overwhelmed!
Why Use a Computer?
"I want to get online,but I'm
oveminelmedl"
[�3 A&Vitles
O 15 Minutes
+Beginner
MEN
n� Q 17.
.. ..
When a learner opens a module, they will see very clearly how many lessons there are, what
they cover, and how long they are. Each module is a video with narration.
Users can also access the course transcript as a PDF under supplemental materials—this
includes the entire text of the module and screen shots. Later in 2016, PLA will be adding
subtitles to the courses, which may help users if they are somewhere where they cannot play
audio or don't have headphones.
The majority of courses are also available in Spanish, and PLA translates new courses as they are
developed. Since launching the site, the most popular classes have been Getting Started on a
Computer, Using a PC, Intro to Email, Basic Search and Navigating a Website. According to our
feedback survey results, 73% of respondents said they used Digital Learn.org to learn how to use
a computer, and 80% of the learners also stated that they learned a new skill through the site.
3
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
PLA and Chicago Public Library
• CPL reviewed 36 online tools, narrowed it to 3
and conducted user testing in branches
• DL was chosen
—Met user needs for level, amount of text, etc.
— Did not track user data, support custom features
• CPL Foundation supported PLA to customize
DigitalLearn with intent to spread to others
' DIGITAL ORG
Thanks to a partnership with Chicago Public Library, PLA can now build customized DigitalLearn
sites for public libraries across the country.
CPL collected information about 36 different curricula and online tools teachers were using. CPL
mapped these widely accepted competencies to the tools their instructional designer reviewed
and narrowed our focus to just those freely available online and aligned with these
competencies.
Self-assessment surveys in libraries throughout the city confirmed that very few CPL learners
are confident with these essential skills:
• Basic computer productivity: (e.g., move the mouse, open a file, create a folder, etc.)
36%
• Basic Internet skills: (e.g., search, download, upload, and send information online) 36%
• Basic online productivity: (e.g., create and manipulate spreadsheets, create
presentations, etc.) 28%
• Intermediate computer productivity: (e.g., use of online services such as job
applications, health services, banking, etc.) 21%
Through several weeks of user testing different training programs, DL was preferred by both
instructors and learners over the other 2 tested tools, which led to the decision to work with
PLA and the DL design team to tweak and customize the tool to meet CPL patrons' needs.
4
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Why Build a Digitall-earn Site?
Libraries can: Learners get:
• Immediately access new DL • Targeted content that
content from PLA develops basic but critical
• Edit elements of PLA skills
courses • Self directed courses they
— Titles, descriptions can complete anytime, at
— Post course resources the library or elsewhere
• Create and easily post • Logins to save progress,
custom course content retrieve certifications
• Receive shared content • Recommendations and a
from other libraries custom course list based on
• Collect user analytics needs
• Co-branding
ODIGITALLEARN.ORG
A PLA INITIATIVE
So in collaboration with the Chicago Public Library, PLA developed a new, personalized interface
for library systems to help them customize DigitalLearn and measure their impact in digital
literacy training. PLA can make this personalized site available to other libraries across the
country.
Through this partnership, PLA and CPL have:
• developed a branded point of entry to the courses for CPL
• developed a user interface to create accounts, take needs assessments, and create and
manage learning plans
• created an administrative interface for CPL staff
Core function improvements include the ability for learners to login/logout and retain their
place, track achievements and courses completed, and establish learning goals.
CPL will also be able to select which of PLA's modules they want to present through their portal
and develop their own modules to post. For instance, they might work with Chicago Public
Schools to develop training modules for parents with children in the schools about how to work
with the school's websites.
5
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Customization Options
Do It Yourself Basic Enhanced
Customization Customization
You use the open You work with PLA to You work with PLA to
source materials to create your own site create your own site
create your own site with a basic, with a level of
predetermined level customization specific
of customization to your needs
SDIGITALLEARN.ORG
IF u A PLA INITIATIVE
PLA is offering libraries three options for building their own DigitalLearn sites.
6
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Do It Yourself
Pros Cons
• No fees/direct costs • Requires time and skills
• Ability to host site of library IT staff
anywhere • No analytics unless your
• Your team can choose staff creates them
to connect courses to • Ongoing management
other library projects, of updates is up to you
sites • No additional support
or TA from PLA/Anneal
ODIGITALLEARN.ORG
®• A PLA INITIATIVE
The Do It Yourself option is best for libraries with sufficient IT staff and experience to set up and
host the site, using the open source files. This can happen at any time and PLA doesn't need to
be involved.
Chicago Public Library - Digital Learn Ili o
Install Dependencies
RVM Posigresgi Redis
Starting a new project using this template
• Clone this project from Gil
• Create a new gemset with Won gemset create cpldl'(assumes rvm is installed)
• Run bundle install
• Run rake db:migrate
Up and Running.
• Ruby version ruby 2.2.3
• Database creation
rake db:create db:migrate
,ow to rvn the test suite github.com/PublicLibraryAssoc
• F
a rspec :testing suite
o ruborop :for syntax and code smells
o hrakeman :for security smells
These are instructions on how to set up a customized DigitalLearn site by going to Github and
replicating the Chicago Public Library site.
7
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Basic Customization
Pros Cons
• Low cost compared to • Fee required
similar services • Only basic flexibility in
• Doesn't burden IT staff customization
or require special skills • Requires initial and
• New features and ongoing commitments
content shared of staff team
automatically • No custom integrations
• Fast build and test cycle with existing programs
• Includes basic analytics or sites
ODIGITALLEARN.ORG
.w A PLA INITIATIVE
Basic customization will be appropriate for most libraries because it is quick and easy, low cost
compared to other subscription services, and easy to manage with whatever staff is available.
More information on the cost and process follows.
https://chipubiib.digitaIlearn.org/
IIIII®
Use a computer to do almost ariyihing!
' DIGITALLEARN.ORG
®. A PLA INITIATIVE
Basic customization will set up a site for your library similar to what is set up for Chicago Public
Library. Visit https://chipublib.digitallearn.org/to see the CPL site.
8
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
https://chipublib.digitaIlearn .org/
r
Use a computer to do almost anything' Creating ._
sumes
Lop N 5ipn VA -�• ��
[j4 Aclivites
021 Minutes
-- + Beginner
'� UU Mn M�wncoevM.e cwnu. novmmaRawrces
CHICAGO
ym.tr�5 ReneJ.m -au,.•
L n.wn
L n�.e1�=N
LIBRAR
PUBLICY a
LIBRAR
ODIGITALLEARN.ORG
A PLA INITIATIVE
Libraries setting up their own sites can decide which fields to require when users register (for
instance, CPL has users affiliate with a branch) and can also post their own "post course"
materials and additional resources for learners.
9
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
CPL Dashboard Apr — May 2016
Most Completed Courses
How Sessions Initiated
l�
Top Referrers
-
p -- — Downloaded Reference
Materials
Sessions by City
-M* Most Viewed Content
ODIGITALLEARN.ORG
.� A PLA INITIATIVE
PLA will set up a Google Analytics site for the library's DigitalLearn site to show basic
information such as how sessions were initiated, were people came from, which courses were
accessed and completed, and which materials were downloaded.
10
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Admin Dashboard
�Change Logln Information Digital Learn Courses
pdate Profile
OUrse These courses are aJfired byrses ha
Zlpcotle)
camplW—Rep.M�byubraryi Course Topic Language Import
Usernccaun[s
CMS pages 6nline Scams S—rhy EngIM Impurtcaurse
Invite Admin
4DIGITALLEARr .ORG
a
Perhaps the most exciting features that PLA and Chicago Public Library have created are the
"back end" features for administrators. We've made it very easy for the library to choose which
courses to publish, edit course descriptions and other features, publish their own courses that
meet local community needs, and get analytics to show funders and other stakeholders how
many people at their branches are using the site and what they are learning. These are all
features that PLA can help set up for other libraries.
On this page, you see the basic Administrator Dashboard. From here, library staff can choose
which courses the present on their personalized site, whether they come from PLA's
DigitalLearn site, or they are new and developed by the library.
Libraries can develop and post their own courses. Right now, course files must be in Articulate
Storyline authoring software, which is what was used to develop DigitalLearn modules. In the
future we expect to be able to allow posting of courses in other formats.
By giving the library tools to develop and post their own courses, we can help libraries directly
address specific community needs. These may be things like:
• collaborating with the local school system on a course that helps parents learn to better
use the school's online parent portal
• Working with city government to develop training on using the city websites to apply for
permits, pay bills, or access other services
• simply translating content of basic computer or Internet courses into a language that's
prominent in the local community
11
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Text copies of the course Additional Resources(post-completion)
Upload any supporting documentation or supplemental materials Upload any supporting documentation or supplemental materials
needed during the course. needed after the course.
—No file chosen No file chosen
(optional)Add a description for this attachment... I (optional)Add a description for this resource...
Add Supplemental Attachment 1 Add Post Course Attachment
Current Supplemental Attachments Current Post-Course Attachments
Res'mepol.pdf Delete HowTOUseWordResumeTemplate.pcil Delete
Resume_Lesson_1.pdf Delete Reaume'remplate.dua—Delete
Resume_Lesson_2,pdf Delete Resume_Builder_user_Gllide,pdf—Delete
Resume_Lesson_3.pdf Delete
Resume_Lesson_4.pdf Delete
Info to help learners practice and use their new skills(post completion)
0 �, B 1 (2 l -E fy -I I F—=t I—I
Now Irs lime la cnata your mums.llaa the how to use a resurne Ieal hantloul W gel.laacb.
H you al¢rtll eul2 flow 10 MM browse resume.amale.IO.I10,uoe tW nesame eu,li ih NB Illi0d5 wo 61 wabieto,ri,will neea to lollow tho o,"a...10
createa user name ar l passworb.After you have-latl an account,kg Into www.Illlrwlsworknel.coMResume antl look for the Resume eullol HIM.
H you neat hat Impronig your re.uma,you may...d it to Meinfuse to gel leebback on hfir hea,You will noad your Chicago F,l llc Ubrery cau to no M.selvir.,3.
Once you ham your resume featly,use a tc apply far Juba.Checkout bnl lob lieangs w the III mis—d a or take a course to learn howm search la lobs Onkne.
Course Topics* Course Language* Course Format
Information Searching
English Desktop
+)oh Search ,
Core
Library staff can post supplemental materials to accompany the courses. They can post
directions to the learners, for after they complete the course. We've called these "info to help
learners practice and use their new skills."
When PLA developed the personalized site for Chicago Public Library, the ability to post
supplemental materials was very important. There were many city and community partners
engaged in their efforts to help Chicago citizens develop computer skills and gain employment
or otherwise participate more successfully in community life. These partners have their own
programs to help people develop resumes, find employment, and more. These features on the
personalized DigitalLearn site give library staff the ability to suggest to learners that they use
their new skills to connect with a local social service agency, or use another city resource to find
a job opening, or make an appointment for counseling—whatever is most appropriate for the
library and its local partners.
12
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Online Job Searching
Courses»Online Job Searching
Use my skills now!(click each link below) Additional Resources
Now that you know how to search for jobs online,checkout local ,y,Center_Working-Familiesmap.pdf
job listings on the following websites: ,#,Job_Search_Organizer.pdf
1.illinois workNetJob Finder- arch by keyword and location. Nearby_Food_Servicejobs.pdf
2.1000 Jobs-Search manufacturing jobs.
3.Government Jobs-Search opportunities by salary and more.
Lac centers ......,o.o..,.,.� . ,,.
Find local centers to help you look and apply for jobs at the Chicago °::�:b��
ook Workforce Partnerships. J" =�"�+•"-a—"R+^"�+"'���
OrvlsittiDisability or ore guidance onyourjob
search.
Other online job-search sites
Indeed.com-One of the most popular job-search sites.You can
search by city,state,or zip code and narrow the results down by
salary,job type,title,and other filters.If you create an account,
you ca save your searches for later use.
DIGITALLEARN.ORG
0 A PLA INITIATIVE
This is an example of what Chicago Public Library has added to DigitalLearn to help job seekers
practice their skills and advance in their job hunt, after completing the Online Job Searching
course.
For instance, they encourage learners to check out local job listings on the "Illinois workNet Job
Finder" site.
They also refer learners to local centers to help them look and apply for jobs—such as
the Chicago Cook Workforce Partnership web site.
They've also posted PDFs with important local information, such as nearby businesses in food
service that are almost always hiring.
13
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Basic Customization Timeline
Libraries opting for the basic customization will work with PLA over a four week period to
develop their sites.
PERIOD ACTIVITY
Pre Work PLA provides library with instruction on preparing logo, palette, copy for editable
sections, desired fields for user info, etc. Library identifies staff team and compiles
initial information.
Week 1 PLA, development team, and library meet virtually to review timeline, roles,
analytic needs, and collected materials.
Week 2 Development team builds customized site. Library team is available as needed for
questions and additional information. Site review meeting is held at end of week.
Week 3 Library team reviews and tests site and provides feedback and questions to PLA.
Corrections and tweaks to customization are possible, but requests for new site
content or functionality may require an additional contract for enhanced
customization.
' Week 4 Final changes are made, analytics go live, and site is launched. PLA provides staff
team with short virtual training on analytics and any other features not yet
covered.
Post Development Updates and fixes to site automatically pushed out. New content is pushed out and
library must edit, approve and publish. Bugs/errors reported to PLA for action.
Requests for new features or enhanced customization considered by PLA on case-
by-case basis. Most will require new contract, but suggestions that improve
functionality of all DL sites may be accommodated by PLA.
14
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Enhanced Customization
Pros Cons
• All the features of basic • Cost may be substantial
customization and more • Timeline may be long
• Can integrate directly • Requires substantial
into other initiatives commitment of library
• Can include support staff team
such as training, • May require ongoing
marketing, etc. contract to maintain
UDIGITALLEARN.ORG
.11 A PLA INITIATIVE
PLA and its contractors are available to work with libraries to develop other features for their
DigitalLearn sites on a case-by-case basis. PLA will meet with the library staff to assess their
needs and develop a proposal for how the site can be adapted.
15
DocuSign Envelope ID:24BBAFA9-CD81-4144-ACEF-E9036E703739
Costs
• Do It Yourself: no cost
• Basic Customization
— $15,000 fee to PLA for initial build, 4-week period of
development and testing, basic training, and launch
• Enhanced Customization:
— Cost TBD based on needs
• Other Services
— Staff training may be arranged separately (on
authoring software, analytics, marketing, stakeholder
engagement, assessing learner needs, measuring
success)
DIGITALLEARN.ORG
• A PLA INITIATIVE
The $15,000 cost for basic customization includes development and one year of hosting. A hosting fee
will be required annually after the first year, and may cost$600-$1,500 (costs will be determined by the
number of sites built, and will go down as additional sites are developed).
16