Loading...
HomeMy WebLinkAbout2024-271-E-Risk Mgr-ClearRisk-Incident management systemRevised 01/24 1 ORANGE COUNTY—INTERNAL USE ONLY ______________________________________________________________________________ Finance Information Vendor Name: ClearRisk Vendor Contact Person: Mike Bowman Phone: 709-727.6424 Address: P.O. box City St. John/s NIL State: Canada Zip: 21097 Department: Revenue Amount: $44,742 Purpose: Incident Management system Budget Code(s): 10-20-250-2501-20-00-630000-Contract Services Vendor # 68507 X Vendor Status with NCSOS: Active Vendor is a BOCC consultant: Yes No Contract Details Contract Type: New Amendment (Original Contract: ) (Most Recent Amendment ) Effective Date 5/13/2024 End Date 5/13/2027 Notice Date (Notice Purpose ) Award Approved by Board (Agenda Date: ); Made or Administered by Signature Authority - BOCC Express Delegation (Agenda Date: ) -Policy 9.4:Under $5,000; Service Under $90,000; Construction Under $250,000 - Budget Policy Section XV (Capital Improvement Project: ) Bidding Informal Bidding ($30k-$90k); Formal RFP ($90k+); Other (<$30k); Exception(# ) Department Affirmation This agreement is approved as to technical form and content and I as Department Director affirmatively state work on this project has not been initiated prior to execution of the agreement. This agreement is approved as to technical form and content. Services related to this agreement have already begun or been completed. Description of the nature of the emergency condition that was addressed: Department Director’s Signature ________________________________________ Date: ________ Information Technologies This agreement has been reviewed and is approved as to information technology content and specifications: Office of the Chief Information Officer___________________________________ Date: ________ Inapplicable because no hardware/software purchases or related services Risk Management This agreement is approved for sufficiency of insurance standards, specifications, and requirements: Office of the Risk Management Officer___________________________________ Date: _________ Financial Services This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act: Office of the Chief Financial Officer ____________________________________ Date: _________ Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney __________________________________________Date: ________ Clerk to the Board All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Received for record retention: Office of the Clerk to the Board __________________________________________Date:_________ DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 5/14/2024 5/14/2024 5/14/2024 5/14/2024 5/14/2024 CLEARRISK SERVICES AGREEMENT THIS SERVICES AGREEMENT (the “Agreement”) is made at St. John’s, in the Province of Newfoundland and Labrador, this day of , 2024 (the “Effective Date”) by and between CLEAR RISK US Corp., a corporation organized and existing under the laws of the State of Delaware (“ClearRisk”) and , a corporation organized and existing under the laws of the State (“Client”). IN CONSIDERATION of the mutual covenants contained herein, ClearRisk and the Client agree as follows: 1.Interpretation 1.1 Definitions. 1.2 “Business Day” means any day other than Saturday, Sunday or a day that is a statutory holiday as observed by the City of St. John’s, in the Province of Newfoundland and Labrador. (a)“ClearRisk” means Clear Risk US Corp. (b)“ClearRisk Service” means ClearRisk’s proprietary online, Web-based risk management solutions, for which Client is granted rights of access and use in accordance with this Agreement, including offline or mobile components or applications as described in the Documentation and any other ancillary services available in connection therewith, as the ClearRisk Service may be updated from time to time by ClearRisk in its sole discretion. (c)“Client” means the entity described above and defined as the Client. (d)“Client Data” means electronic data and information submitted by or for Client to the ClearRisk Service. 1.3 “Data Protection Laws” means all laws and regulations, including laws and regulations of Canada and the United States (including the Personal Information Protection and Electronic Documents Act (Canada), the Canadian Anti-Spam Legislation and the California Consumer Privacy Act), applicable to the Processing of Personal Information under the Agreement. (a)“Documentation” means the user documentation for the ClearRisk Service found within Client’s ClearRisk Service instance and its usage guides and policies, as updated from time to time, accessible via the ClearRisk Service. (b)“Fees” mean Subscription Fees, and Professional Services Fees, as applicable. (c)“Malicious Code” means code, files, scripts, agents or programs intended to do harm, including, for example, viruses, worms, time bombs and Trojan horses. (d)“Party” means ClearRisk or Client and “Parties” means ClearRisk and Client. (e)“Personal Information” means any information relating to an identified or identifiable natural person as defined under applicable Data Protection Laws. (f)“Processing” means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. 13th May Orange County Government North Carolina DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -2 - (g)“Professional Services” means the implementation, training and other services provided by ClearRisk pursuant to a Statement of Work. (h)“Professional Services Fees” means the fees for Professional Services set forth in Schedule A or in the applicable Statement of Work. (i)“Salesforce Platform” means the SFDC proprietary online, web-based platform service described in the SFDC Service Agreement. (j)“SFDC” means Salesforce.com, Inc. (k)“SFDC Service Agreement” means the Salesforce.com, Inc. service agreement located at https://www.clearrisk.com/SFDCSA and which governs Client’s use of the ClearRisk Service on the Salesforce Platform. (l)“Statement of Work” means a statement of work for Professional Services entered into by Clear Risk and Client which refers to this Agreement. (m)“Subscription Fee” means the fee payable by Client as set out in Schedule A. (n)“Support Services” means the technical support services for the ClearRisk Service provided by ClearRisk in accordance with Section 3.4 hereof. (o)“Term” means the Initial Term and any Renewal Terms (each as defined in Section 2 hereof). (p)“User” means an individual who is authorized by Client to use the ClearRisk Service or for whom the ClearRisk Service has been provisioned, and to whom Client has supplied a user identification and password. Users may include, for example, employees, consultants, contractors and agents of Client. 1.4 Rules of Interpretation. Words importing the singular number shall include the plural and vice versa and words importing the use of any gender shall include all genders. Headings used in this Agreement are for convenience of reference only and shall not constitute a part of this Agreement for any other purpose including, without limitation, its interpretation. Expressions such as “hereof”, “hereunder” and “he re by” shall be construed as referring to the entire Agreement and not only to the particular Artic le, section, subsection or clause in which they appear. In determining beneficial ownership by a person, such person shall be considered as having a beneficial ownership interest in the assets of any company controlled, directly or indirectly, by such pers on. This Agreement shall not be construed or interpreted so as to create any rights to or be enforceable by any person who or which is not now, or does not in future become, a party to this Agreement. 1.5 Business Days. In the event that any act is required hereunder to be done, any notice is required hereunder to be given, or any period of time is to expire hereunder on any day that is not a Business Day, such act shall be required to be done or notice shall be require d to be given or time shall expire on the next succeeding Business Day. 1.6 Schedules. The following Schedules are attached hereto and form part of this Agreement: Schedule A – Fee Schedule Schedule B – Initial Statement of Work DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -3 - 2.Term 2.1 Term of Agreement. This Agreement comes into force as of the Effective Date hereof and has an initial term of three (3) years from the Effective Date (the “Initial Term”), unless terminated earlier in accordance with the provisions of this Agreement or applicable law or it is renewed in accordance with Section 2.2 hereof. 2.2 Auto-Renewal Unless Terminated. This Agreement shall renew for succeeding three (3) year terms (each a “Renewal Term”) unless a Party notifies the other Party of its intention not to renew this Agreement no less than 30 days prior to the expiration of the Initial Term or any Renewal Term. 2.3 Fee Changes. At the end of the Initial Term of this Agreement and any subsequent Renewal Terms, ClearRisk may adjust the Subscription Fees payable under this Agreement by providing Client written notice of such adjustment at least 60 days prior to the beginning of the Renewal Term. 3.The ClearRisk Service 3.1 Grant of Right to Use the ClearRisk Service . Subject to the terms and conditions of this Agreement and payment of the applicable Fees, ClearRisk hereby grants to Client a non-exclusive, worldwide, non- transferable, non-sublicensable right to (a) access and use (and to permit Users to access and use) the ClearRisk Service, solely during the Term; and (b) access and use, and to permit Users to access and use, the Documentation as reasonably necessary to support the Client’s permitted use of the ClearRisk Service during the Term. 3.2 SFDC Service Agreement. Client acknowledges that the ClearRisk Service is provided on the Salesforce Platform and hereby agrees that the terms and conditions set forth in the SFDC Service Agreement are hereby incorporated by reference and form part of this Agreement and Client hereby agrees to be bound by the SFDC Service Agreement. Client acknowledges and agrees that the terms set out in the SFDC Service Agreement are imposed upon ClearRisk by SFDC and a breach by Client of the terms and conditions set forth therein constitutes a material breach of this Agreement and could impact and/or prevent Client from being able to access and use the ClearRisk Service. 3.3 Restrictions. Client shall not (and shall not allow Users or any third party to): (a) possess, download or copy the ClearRisk Service or any part of the ClearRisk Service, including but not limited any component which comprises the ClearRisk Service, but not including any output from the ClearRisk Service; (b) knowingly interfere with service to any of ClearRisk’s customers, users, host or network, including by means of intentionally submitting a virus, overloading, flooding, spamming, mail bombing or crash ing; (c) modify, translate, reverse engineer, decompile, disassemble, or create derivative works based on the ClearRisk Service and/or Documentation, except to the extent that enforcement is prohibited by applicable law; (d) circumvent any timing restrictions that are built into the ClearRisk Service; (e) sell, rent, lend, transfer, distribute, license, or grant any rights in the ClearRisk Service or Documentation in any form to any person without the written consent of ClearRisk; (f) remove any proprietary notices, labels, or marks from the ClearRisk Service or Documentation; (g) create any “links” to or “frame” or “mirror” of the ClearRisk Service or any portion thereof; or (h) use the ClearRisk Service in violation of applicable laws. 3.4 Support. During the Term, ClearRisk, or its authorized support partner, will provide Support Services at no additional charge. Support Services will include: (a) email support is monitored and provided from 8:00 AM to 5:00 PM (ET) ON BUSINESS DAYS and emails outside of these hours will be responded to on a reasonable efforts basis; and (b) ClearRisk will use commercially reasonable efforts to respond to support enquiries within one (1) Business Day. Customer will have access to ClearRisk’s technical support web site and may use the web site to submit service requests. ClearRisk shall not be required to provide Support Services if Client is in default of any of its material obligations under this Agreement. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -4 - 3.5 Professional Services. If agreed to in a Statement of Work, ClearRisk, or its authorized services partner, will provide Professional Services on a time and materials basis for the Professional Services Fees set forth in Schedule A and in accordance with the terms and conditions in the applicable Statement of Work. The initial Statement of Work for implementation of the ClearRisk Service is attached hereto as Schedule B. 4.Client Data and Personal Information 4.1 Ownership. As between ClearRisk and Client, Client exclusively owns all rights, title and interest in and to all Client Data. ClearRisk does not acquire any rights, title or ownership interest of any kind whatsoever, express or implied, in any of the Client Data. 4.2 Technical and Organizational Safeguards . In connection with the provision of the ClearRisk Service, ClearRisk will maintain commercially reasonable administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Client Data. Those safeguards will include, but will not be limited to, measures for preventing access, use, modification or disclosure of Client Data by ClearRisk personnel except (a) to provide the ClearRisk Service and prevent or address service or technical problems, (b) as compelled by law in accordance with Section 9.4 below and upon identification of lawful authority, or (c) as expressly permitted in writing by Client. ClearRisk shall not access Client Data except to provide the ClearRisk Service and prevent or address service or technical problems, or at Client’s request in connection with customer support matters. 4.3 Client Data and Portability. Upon request by Client made during the Term or within thirty (30) days after the effective date of termination of this Agreement, Clear Risk will make the Client Data available to Client for export or download as provided in the Documentation. After such 30-day period, Clear Risk will have no obligation to maintain or provide any Client Data, and will thereafter delete or destroy all copies of Client Data in its systems or otherwise in its possession or control as provided in th e Documentation, unless legally prohibited. 4.4 Personal Information. To the extent that Client Data includes Personal Information: (a)ClearRisk’s Processing of Personal Information. ClearRisk shall secure Personal Information with all necessary safeguards appropriate to the level of sensitivity of the Personal Information. ClearRisk shall only Process Personal Information in accordance Data Protection Laws and only for the following purposes: (i) Processing in accordance with the Agreement; (ii) Processing initiated by Client’s Users or customers in their use of the ClearRisk Service; and (iii) Processing to comply with other documented r easonable instructions provided by Client where such instructions are consistent with the terms of the Agreement. (b)California Consumer Privacy Act (“CCPA”). ClearRisk is a “Service Provider” as such term is defined under §1798.140(v) of the CCPA. As such ClearRisk shall not retain, use or disclose any Personal Information received from the Client during the Term for any purpose other than the specific purpose of providing the ClearRisk Service and other related services specified in this Agreement or for such other business purpose as is specified in this Agreement. (c)ClearRisk Personnel. ClearRisk shall ensure that its personnel engaged in the Processing of Personal Information are informed of the confidential nature of the Personal Information and have received appropriate training on their responsibilities and ClearRisk shall take commercially reasonable steps to ensure the reliability of any ClearRisk personnel engaged in the Processing of Personal Information. (d)Client’s Obligations. Client’s instructions to ClearRisk for the Processing of Personal Information shall comply with Data Protection Laws. Client shall have sole responsibility for the accuracy, quality, and legality of Personal Information and the means by which Client acquired Personal Information. Client hereby represents and warrants to, and covenants with ClearRisk that Client Data will only contain Personal Information in respect of which Client has provided all notices and disclosures, obtained all applicable third party consents and permissions and otherwise has all authority, in each case as required by applicable DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -5 - Data Protection Laws, to enable ClearRisk to provide the ClearRisk Service, including with respect to the Processing of Personal Information, including by or to ClearRisk and to or from all applicable third parties. (e)Security Incident . Upon becoming aware of any unlawful access to any Personal Information, any unauthorized access to such facilities or equipment resulting in loss, disclosure or alteration of any Personal Information, or any actual loss of or suspected threats to the security of Personal Information (including any physical trespass on a secure facility, computing systems intrusion/hacking, loss/theft of a computing device, storage media or printed materials, or other unauthorized access) (each a “Security Incident”), ClearRisk will promptly notify Client of the Security Incident (and in all circumstances at least as soon as it reports to similarly situated customers of Client, but in any event as soon as reasonably possible in the circumstances), and will investigate or perform required assistance in the investigation of the Security Incident and provide Client with detailed information about the Security Incident. ClearRisk will take all commercially reasonable steps to mitigate the effects of the Security Incident, or assist Client in doing so; and will provide prior notice to Client of, and will not undertake any, proposed communications to third parties related to a Security Incident involving Personal Information without Client’s prior written approval, not to be unreasonably withheld, conditioned or delayed. ClearRisk will work with and coordinate with Client on any such notices in any event. Subject to Section 13, ClearRisk will comply with this Section 4.4(e) at ClearRisk’s cost, unless the Security Incident arose from Client’s negligent or willful acts or ClearRisk’s compliance with Client’s express written instructions. (f)Request for Personal Information. ClearRisk shall (at Client’s expense) taking into account the nature of the processing, provide all reasonable cooperation to assist Client by appropriate technical and organisational measures, in so far as is possible, to respond to any requests from individuals or applicable data protection authorities relating to the Processing of Client Personal Information under this Agreement. In the event that any such request is made to ClearRisk directly, ClearRisk shall not respon d to such communication directly without Client’s prior authorization, unless legally compelled to do so. If ClearRisk is required to respond to such a request, ClearRisk shall promptly notify Client and provide it with a copy of the request unless legally prohibited from doing so. 5.Client Responsibilities 5.1 Users. Client is responsible for all activities that occur in User accounts and for its and its Users’ compliance with this Agreement. Client shall: (a) have sole responsibility for the accuracy, quality, integrity, legality, reliability, and appropriateness of all Client Data and the means by which Client acquired Client Data; (b) use commercially reasonable efforts to prevent unauthorized access to, or use of, the ClearRisk Service, and notify ClearRisk promptly of any such unauthorized access or use; and (c) use the ClearRisk Service only in accordance with the Documentation and applicable laws and government regulations. 5.2 Equipment. Client is solely responsible for acquiring, servicing, maintaining and updating all equipment, computers, software and communications services (such as Internet access) that are required to allow Client to access and use the ClearRisk Service and for all expenses relating thereto. Client agrees to access and use, and shall ensure that all Users access and use, the ClearRisk Service in accordance with any and all operating instructions or procedures that may be issued by ClearRisk from time to time. 6.Fees and Payment Terms 6.1 Fees. Client agrees to pay the Fees and other charges for the ClearRisk Service and Professional Services provided under this Agreement as specified in Schedule A. Except as otherwise specified herein, payment obligations are non-cancellable and Fees paid are non-refundable, 6.2 Annual Cost Escalation. Client agrees that all Subscription Fees will increase by 5% each and every year at the anniversary date. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -6 - 6.3 Taxes. All amounts payable hereunder are exclusive of any and all taxes, and Client is responsible for payment of such taxes (excluding taxes based on ClearRisk’s net income). All prices are stated, and Client shall pay, in US dollars. 6.4 Invoicing and Payment. Fees will be invoiced in advance and unless otherwise stated herein, charges are due upon receipt of invoice. 6.5 Interest on Overdue Amounts. Payment received by ClearRisk after the due date shall be subject to a late fee equal to one and one-half percent (1.5%) per month, or, if less, the maximum amount allowed by applicable law. 6.6 Suspension for Non-Payment. ClearRisk may immediately suspend Client’s access to and use of the ClearRisk Service if Client fails to make any payment due in respect of the ClearRisk Service and does not cure such non-payment within ten (10) Business Days after receiving notice of such failure. Any suspension of the rights hereunder by ClearRisk under the preceding sentence shall not excuse Client from its obligation to make all payment(s) under the Agreement. 6.7 Payment Disputes. ClearRisk will not exercise its rights under Section 6.5 (Interest on Overdue Amounts) or 6.6 (Suspension for Non-Payment) above if Client is disputing the applicable charges reasonably and in good faith and are cooperating diligently to resolve the dispute. 7.Audits ClearRisk shall have the right, with reasonable notice and during normal business hours, at ClearRisk’s sole expense and in as non-disrupting a manner as reasonably possible, to verify Client’s compliance with Client’s obligations hereunder through a remote or an on-site audit of Client’s records, facilities and licensing processes by ClearRisk or a third party representative of ClearRisk. Client shall permit up to one such audit per year, including once during the 12 month period following the termination of this Agreement for any reason. ClearRisk may use such audit reports solely to enforce its rights hereunder and shall otherwise treat audit reports and any information received in connection with such audits as Confidential Information. In the event that an audit establishes that Client is in material breach of its obligations hereunder, Client shall reimburse ClearRisk for the cost of the audit and shall promptly pay to ClearRisk all outstanding Fees. 8.Intellectual Property 8.1 The ClearRisk Service. Subject to the limited rights expressly granted hereunder, ClearRisk reserves all rights, title and interest in and to the ClearRisk Service, including all related intellectual property rights. No rights are granted to Client hereunder other than as expressly set forth in this Agreement. ClearRisk retains all right, title and interest in and to the ClearRisk Service at all times, and regardless of the form or media in or on which the original or other copies may subsequently exist. Fi nally, any suggestions, ideas or inventions that Client, its employees or agents, voluntarily and optionally disclose to ClearRisk through any means will be used, or not used, by us at ClearRisk’s sole discretion; and, ClearRisk will have no obligation to Client, its employees and/or agents regarding any ideas or inventions that Client, its employees and/or agent disclose through such means. 8.2 Usage Data. Notwithstanding anything to the contrary in this Agreement, Client acknowledges that the ClearRisk Service may provide Usage Data (as hereinafter defined) to ClearRisk and ClearRisk may monitor Client’s use of the ClearRisk Service and collect and compil e aggregated and anonymized data, information, analytics and diagnostic statistics relating to the provision and operation, and Client’s use, of the ClearRisk Service (“Usage Data”). As between ClearRisk and Client, all right, title, and interest in Usage Data, including all intellectual property rights therein, are owned solely by ClearRisk. ClearRisk may use Usage Data to support (including to improve) the ClearRisk Service, develop new products and services, DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -7 - and for any other business purpose, provided that the Usage Data does not contain any Personal Information or other user identifier and is not associated with Client or any User. 8.3 Feedback. Client may provide reasonable feedback to ClearRisk including, but not limited to, suitability, problem reports, suggestions, enhancement request, recommendation, correction, and other information with respect to the operation of the ClearRisk Service (“Feedback”). Client hereby grants to ClearRisk a fully paid-up, royalty-free, worldwide, assignable, transferable, sublicenseable, irrevocable, perpetual license to use or incorporate into the ClearRisk Service, the Documentation and any other Clear Risk products or services, or for any other purposes, any Feedback provided by Client or its Users. 9.Confidentiality 9.1 Definition of Confidential Information. As used herein, “Confidential Information” means all confidential and proprietary information of a Party (“Disclosing Party”) disclosed to the other Party (“Receiving Party”), whether orally or in writing, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure, including the terms and conditions of this Agreement (including pricing), the Service and Documentation, Client Data (which is the Confidential Information of the Client), business and marketing plans, technology and technical information, product designs, and business processes. Confidential Information shall not include any information that: (i) is or becomes generally known to the public without breach of any obligation owed to the Disclosing Party; (ii) was known to the Receiving Party prior to its disclosure by the Disclosing Party without breach of any obligation owed to the Disclosing Party; (iii ) was independently developed by the Receiving Party without breach of any obligation owed to the Disclosing Party; or (iv) is received from a third party without breach of any obligation owed to the Disclosing Party. 9.2 Confidentiality. Subject to Section 9.4 below, and unless the Disclosing Party expressly agrees in writing otherwise, the Receiving Party will: (a) use the Disclosing Party’s Confidential Information only during the Term and only as necessary to perform the Receiving Party’s obligations under this Agreement; (b) disclose the Disclosing Party’s Confidential Information only to the Receiving Party’s directors, officers, agents, employees and authorized subcontractors and their employees and only to the extent that such disclosure is necessary to perform the Receiving Party’s obligations or exercise the Receiving Party’s rights under this Agreement. Client shall not disclose any performance, benchmarking, or feature-related information about the ClearRisk Service. 9.3 Protection. Each Party agrees to protect the confidentiality of the Confidential Information of the other Party in the same manner that it protects the confidentiality of its own proprietary and confidential information of like kind (but in no event using less than reasonable care). 9.4 Compelled Disclosure. If the Receiving Party is compelled by law to disclose Confidential Information of the Disclosing Party, it shall provide the Disclosing Party with prior notice of such compelled disclosure (to the extent legally permitted) and reasonable assistance, at Disclosing Party’s cost, if the Disclosing Party wishes to contest the disclosure. 9.5 Remedies. If the Receiving Party discloses or uses (or threatens to disclose or use) any Confidential Information of the Disclosing Party in breach of confidentiality protections hereunder, the Disclosing Party shall have the right, in addition to any other remedies available to it, to seek injunctive relief to enjoin such acts, it being specifically acknowledged by the Parties that any other available remedies may be inadequate. 9.6 Return of Confidential Information. Upon Disclosing Party’s written request upon expiration or termination of this Agreement (or at any earlier time upon written request by the Disclosing Party), the Receiving Party will: (a) promptly deliver to the Disclosing Party all originals and copies, in whatever form or medium, of all the Disclosing Party’s Confidential Information and all documents, records, data and materials, in whatever form or medium, containing such Confidential Information in the Receiving Pa rty’s possession, power or DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -8 - control and the Receiving Party will delete all of the Disclosing Party’s Confidential Information from any and all of the Receiving Party’s computer systems, retrieval systems and databases; and (b) request that all persons to whom it has provided any of the Disclosing Party’s Confidential Information comply with this Section 9.6. 10.Warranties and Disclaimers 10.1 Limited Warranties . ClearRisk hereby represents and warrants to Client that: (a)During the Term the ClearRisk Service will perform materially in accordance with the Documentation therefor; and (b)the ClearRisk Service will not contain any Malicious Code. 10.2 Warranty Disclaimers. EXCEPT FOR THE EXPRESS WARRANTIES PROVIDED HEREIN, CLEARRISK PROVIDES THE CLEARRISK SERVICE ON AN “AS IS” AND “AS AVAILABLE” BASIS. CLEARRISK MAKES NO OTHER REPRESENTATIONS OR WARRANTIES, AND THERE ARE NO CONDITIONS, GUARANTEES, REPRESENTATIONS OR WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, (INCLUDING WITHOUT LIMITATION ANY EXPRESS OR IMPLIED WARRANTIES OR CONDITIONS OF QUALITY, PERFORMANCE, RESULTS, FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY OR ARISING BY STATUTE OR OTHERWISE IN LAW OR FROM A COURSE OF DEALING OR USAGE OF THE TRADE) AS TO, ARISING OUT OF OR RELATED TO THE FOLLOWING: (I) THIS AGREEMENT; (II) THE CLEARRISK SERVICE; OR (III) SECURITY ASSOCIATED WITH THE TRANSMISSION OF INFORMATION OR CLIENT DATA TRANSMITTED TO OR FROM THE CLEARRISK SERVICE. CLEARRISK ALSO DISCLAIMS ALL LIABILITY WITH REGARD TO CLIENT’S VIEWING OF ANY WEB SITES THAT MAY BE LINKED FROM THE CLEARRISK SERVICE. CLEARRISK DOES NOT REPRESENT OR WARRANT THAT THE CLEARRISK SERVICE WILL MEET ANY OR ALL OF CLIENT’S PARTICULAR REQUIREMENTS, THE RESULTS THAT MAY BE OBTAINED FROM THE USE OF THE CLEARRISK SERVICE WILL BE RELIABLE, THE QUALITY OF ANY PRODUCTS OBTAINED OR PURCHASED THROUGH THE USE OF THE CLEARRISK SERVICE WILL MEET CLIENT’S EXPECTATIONS OR THAT THE CLEARRISK SERVICE WILL OPERATE ERROR-FREE OR UNINTERRUPTED. THIS DISCLAIMER OF WARRANTY CONSTITUTES AN ESSENTIAL PART OF THIS AGREEMENT. 11.Intellectual Property Infringement Indemnification 11.1 Indemnification by ClearRisk. Subject to this Agreement, ClearRisk shall defend, indemnify and hold Client harmless against any loss, damage or costs (including reasonable legal fees) incurred in connection with claims, demands, suits, or proceedings made or brought against Client by a third party alleging that the use of the Service and Documentation as contemplated hereunder infringes the intellectual property rights of a third party (each an “Infringement Claim”); provided, that Client (a) promptly gives written notice of the Infringement Claim to ClearRisk; (b) gives ClearRisk sole control of the defense and settlement of the Infringement Claim (provided that ClearRisk may not settle or defend any Infringement Claim unless it unconditionally releases Client of all liability); and (c) provides to ClearRisk, at ClearRisk ’s cost, all reasonable assistance and information. 11.2 Other Remedies. In addition to the indemnity contained in Section 11.1, if (a) ClearRisk becomes aware of an actual or potential Infringement Claim, or (b) Client provides ClearRisk with notice of an actual or potential Infringement Claim, ClearRisk may (or in the case of an injunction against Client, shall), at ClearRisk’s sole option and determination: (i) procure for Client the right to continue to use the ClearRisk Service; or (ii) replace or modify the ClearRisk Service with an equivalent or better ser vice so that Client’s use is no longer infringing; or (iii) if (i) and (ii) are not commercially reasonable, as determined by ClearRisk in its sole discretion, terminate the rights granted hereunder to the Client to access and use the ClearRisk Service and refund to Client that portion of any prepaid Subscription Fees that is applicable to the period DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -9 - following the termination of the Agreement pursuant to this Section 11.2, less any outstanding Subscription Fees owed on such affected portion of the ClearRisk Service. 11.3 Exclusions. The indemnity in Section 11.1 does not extend to (a) any Infringement Claim based upon infringement or alleged infringement of any patent, trademark, copyright or other intellectual property right by the combination of the ClearRisk Service with other products, software or services not provided or approved by ClearRisk, if such infringement would have been avoided but for such combination; or (b) any use, distribution or sublicensing in breach of or outside the scope of this Agreement. 11.4 Sole Remedies. THIS SECTION 11 CONTAINS CLEARRISK’S ENTIRE LIABILITY, AND CLIENT’S SOLE AND EXCLUSIVE REMEDIES, FOR INFRINGEMENT CLAIMS. 12.Indemnification by Client To the extent authorized by North Carolina law, Client will defend ClearRisk against any claim, demand, suit or proceeding made or brought against ClearRisk by a third party alleging that Client Data, or Client’s use of the ClearRisk Service in breach of this Agreement, infringes or misappropriates such third party’s intellectual property rights or violates applicable law (a “Claim”), and will indemnify ClearRisk from any damages, legal fees and costs finally awarded against ClearRisk as a result of, or for any amounts paid by ClearRisk under a court-approved settlement of, a Claim, provided that ClearRisk (a) promptly gives Client written notice of the Claim, (b) gives Client sole control of the defense and settlement of the Claim (except that Client may not settle any Claim unless it unconditionally releases ClearRisk of all liability), and (c) gives Client all reasonable assistance, at Client’s expense. 13.Limitation of Liability 13.1 Exclusion of Indirect and Consequential Damages. SUBJECT TO SECTION 13.3 HEREOF, IN NO EVENT SHALL EITHER PARTY HAVE ANY LIABILITY TO THE OTHER PARTY FOR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF BUSINESS, LOSS OF PROFITS, BUSINESS INTERRUPTION, LOSS OF DATA, LOST SAVINGS OR OTHER SIMILAR PECUNIARY LOSS). 13.2 Limitation of Liability for Direct Damages. SUBJECT TO SECTION 13.3 HEREOF, IN NO EVENT WILL EITHER PARTY’S MAXIMUM CUMULATIVE LIABILITY UNDER THIS AGREEMENT ARISING OUT OF OR RELATED TO THIS AGREEMENT OR RELATING TO THE SUBJECT MATTER HEREOF FOR ALL CLAIMS, COSTS, LOSSES AND DAMAGES EXCEED THE APPLICABLE INSURANCE AMOUNTS AS SET FORTH IN PARAGRAPH 14. THE EXISTENCE OF MORE THAN ONE CLAIM SHALL NOT ENLARGE THIS CUMULATIVE LIMIT. 13.3 Certain Damages Not Excluded or Limited. NOTWITHSTANDING THE FOREGOING, NO LIMITATION OF EITHER PARTY’S LIABILITY SET FORTH IN THIS AGREEMENT SHALL APPLY TO (I) DAMAGES ARISING FROM A PARTY’S BREACH OF ITS CONFIDENTIALITY OBLIGATIONS HEREUNDER, EXCEPT AS IT RELATES TO RELEASES OF INFORMATION PURSUANT TO NORTH CAROLINA PUBLIC RECORDS LAW; (II) INDEMNIFICATION CLAIMS, (III) DAMAGES ARISING FROM INFRINGEMENT OF A PARTY’S INTELLECTUAL PROPERTY RIGHTS; (IV) ANY CLAIMS FOR NON - PAYMENT, (V) FRAUD OR WILLFUL MISCONDUCT, OR (VI) BODILY INJURY OR DEATH. 13.4 Application of Exclusions and Limitations. The foregoing limitations and exclusions of liability shall apply even if a Party had been advised of the possibility of any such costs, losses or damages or knew or ought to have known of such costs, losses or damages and shall apply regardless of whether the action arose in contract, including, without limitation, from a fundamental breach, or breach of a condition, fundamental term or warranty, or in tort (including, without limitation negligence) or otherwise. The foregoing provisions limiting the liability of ClearRisk shall also apply to its officers, directors, employees, and agents as trust DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -10 - provisions for the benefit of such officers, directors, employees, and agents and shall be enforceable by such persons as trust beneficiaries. 14.Insurance 14.1 Coverage. At all times during the Term and for so long as any Statement of Work has not yet expired or been terminated, ClearRisk shall maintain, at its sole cost and expense, all insurance coverage required by applicable law, and in any event insurance coverage in the following types and amounts: (a)Commercial General Liability with limits no less than One Million Dollars ($1,000,000) per occurrence, and Two Million Dollars ($2,000,000) in the aggregate for claims each policy year, including bodily injury and property damage and products and completed operations and advertising liability, which policy will include contractual liability coverage insuring the activities of ClearRisk under this Agreement and have a deductible of not more than ten thousand dollars ($10,000.00); (b)Umbrella Liability that provides additional coverage over primary comprehensive general liability coverage, automobile liability, and employers’ liability limits, in an amount not less than Five Million Dollars ($5,000,000) per occurrence; (c)Worker’s Compensation and employer’s liability insurance with statutory limits of the minimum amount required by applicable law of the jurisdiction in which the work is performed; (d)Cyber Liability Insurance, with limits of no less than One Million Dollars ($1,000,000) per occurrence and Two Million Dollars ($2,000,000) in the aggregate for claims each policy year; (e)Professional Liability or Technology Errors and Omissions with no less than One Million Dollars ($1,000,000) per occurrence for coverage for loss or disclosure of electronic data, media and content rights infringement and liability, network security failure and software copyright infringement. 14.2 Policy Terms. ClearRisk will keep all insurance coverage current and in force during the Term of this Agreement, and such insurance coverage must be (i) written through an insurance carrier with an overall A.M. Best Rating of A or better, and (ii) name Client as an additional insured under the general liability insurance provisions of the policy with respect to liability arising from or out of the ClearRisk Service by Client. 14.3 Cancellation. The insurance policy shall apply as primary insurance and contain an undertaking by the insurers to notify Client in writing not less than 30 days’ prior to any material change, cancellation or termination and that ClearRisk itself will notify Client within 48 hours of receipt of notification by insurers of any cancellation or termination of the insurance policy. 14.4 Certificates of Insurance. Upon the written request of Client, ClearRisk will provide Client with copies of the certificates of insurance and policy endorsements for all insurance coverage required by this Section, and shall not do anything to invalidate such insurance coverage. C learRisk shall give 30 days’ prior written notice to Client of any cancellation, non-renewal, or material change in coverage, scope, or amount of any insurance policy required by or affecting the Client’s rights or remedies under this Agreement. 15.Termination 15.1 Termination. A Party may terminate this Agreement for cause (a) upon 30 days’ written notice to the other Party of a material breach if such breach remains uncured at the expiration of such period, or (b) if the other Party becomes the subject of a petition in bankruptcy or any other proceeding relating to insolvency, receivership, liquidation or assignment for the benefit of creditors. 15.2 Effect of Termination. Upon the termination of this Agreement: DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -11 - (a)by ClearRisk pursuant to Section 15.1(a), such termination shall not prevent ClearRisk from collecting from Client any amounts or payments owing that accrued prior to termination and Client will also be obligated to pay to ClearRisk unpaid Fees covering the remainder of the then-current Term; (b)by Client pursuant to Section 15.1(a), such termination shall not relieve Client of any obligations that have accrued as of the date of such termination, including, without limitation, any sums or payments then due; (c)for any reason, each Party shall return to the other Party all copies of the other Party’s Confidential Information in its possession or control. 15.3 Data Provided Upon Termination. Upon the termination of this Agreement for any reason, ClearRisk shall, if requested by Client within 30 days of the effective termination date, backup Client’s Client Data and provide electronic copies of such Client Data through a ClearRisk provided FTP folder to Client. All data will be uniquely identified for efficient processing. Client Data will be provided as follows: ●Text data in CSV format with appropriate titles and column headers; ●Notes and file attachments in their native format provided in .zip folder; and ●Once data is accepted by Client, ClearRisk will delete all data from existing servers and provide confirmation to Client. After such 30-day period, ClearRisk will have no obligation to maintain or provide any Client Data, and will thereafter delete or destroy all copies of Client Data in its systems or otherwise in its possession or control, unless legally prohibited. Once Client Data has been provided to Client as described above, ClearRisk will have no further responsibility to Client. 15.4 Suspension of Access to the ClearRisk Service. In addition to any termination rights of ClearRisk pursuant to this Agreement, extraordinary circumstances may require ClearRisk to suspend or terminate (where appropriate), as determined in ClearRisk’s reasonable discretion, Client’s access to and/or us e of, or otherwise modify, the ClearRisk Service in order to: (a) prevent material damages to, or material degradation of the integrity of, ClearRisk’s or its provider’s Internet network; or (b) comply with any law, regulation, court order, or other governmental order. ClearRisk will notify Client of such suspension or termination action as far in advance of such suspension or termination as reasonably possible, and if such advance notice is not possible, then as soon as possible after such suspension or termination. In the event of a suspension, ClearRisk will limit such suspension to that which is minimally required and will promptly restore Client’s access to the ClearRisk Service as soon as the event giving ri se to the suspension has been addressed (including by Client agreeing to accept the risks associated with such suspension) or resolved. Unless caused by a breach of this Agreement by Client: (i) all Subscription Fees related to the use of the ClearRisk Service or other suspended services shall be waived for the duration of the suspension and any such waived Subscription Fees which have been pre -paid shall be refunded to Client; and (ii) in the event of a termination in connection with this Section 15.4, Cli ent shall receive a refund of any and all prepaid Subscription Fees applicable to the remainder of the then-current Term. 16.Miscellaneous 16.1 Force Majeure. In the event that either Party is prevented from performing, or is unable to perform, any of its obligations under this Agreement due to any cause beyond the reasonable control of the Party invoking this provision (including, without limitation, for causes due to war, fire, earthquake, flood, hurricane, riots, acts of God, telecommunications outage not caused by the obligated Party, epidemics, pandemics or other similar causes) (“Force Majeure Event”), the affected Party’s performance will be excused and the time for performance will be extended for the period of delay or inability to perform due to such occurrence; provided that the affected Party: (a) provides the other Party with prompt notice of the nature and expected duration of the Force Majeure Event; (b) uses commercially reasonable efforts to address and mitigate the cause and effect of such Force Majeure Event; (c) provides periodic notice of relevant developments; and DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -12 - (d) provides prompt notice of the end of such Force Majeure Event. Obligations to pay are excused only to the extent that payments are entirely prevented by the Force Majeure Event. 16.2 Further Assurances. The Parties and each of them shall at any time and from time to time do, execute, acknowledge and deliver or cause to be done, executed, acknowledged and delivered all such further acts, deeds, assignments, transfers, conveyances, powers of attorney and assurances as may be reasonably required so as to accomplish and carry into effect the intentions of this Agreement. 16.3 Waiver of Breach. No delay or omission of either of the Parties to exercise any right or power accruing upon any default or breach under this Agreement shall impair any such right or power or shall be construed to be an acquiescence therein or waiver of any such default or breach or of any right or power accruing upon any such default or breach or any subsequent default or breach under this Agreement. 16.4 Waiver of Term. None of the conditions, covenants or agreements contained in this Agreement may be waived in whole or in part unless such waiver is in writing and signed by the Party in whose favor the representations, warranties, conditions, covenants or agreements so waived operate. 16.5 Publicity. Client agrees: (i) to issue a joint press release with ClearRisk (“Press Release”) on a mutually agreed date within thirty (30) days of the Effective Date announcing that Client has entered into an agreement to use the ClearRisk Service; and (ii) that ClearRisk may disclose that Client is a Client of ClearRisk. Client will have the right to review and approve the Press Release in advance; such approval shall not be unreasonably delayed or withheld. Each Party may include the name and logo of the other Party in lists of clients or vendors in accordance with the other Party’s standard guidelines. 16.6 Assignment and Sublicenses. Client shall not be permitted to assign this Agreement or any of its obligations hereunder without the prior written consent of ClearRisk, which consent may be withheld by ClearRisk in its sole discretion. Client also agrees that it shall not have the right to grant sublicenses under this Agreement without the prior written agreement of ClearRisk. If the Client is acquired by, sells substantially all of its assets to, or undergoes a change of control in favor of, a direct competi tor of ClearRisk, then ClearRisk may terminate this Agreement upon written notice. 16.7 Notice. Any notice or other document required or permitted to be given to any Party hereunder shall be validly given if delivered personally (including by courier service) or sent by email addressed to the addressee thereof at the following respective addresses: (a)if to ClearRisk at: PMB #111 2801 Centerville Road First Floor Wilmington, Delaware 19808-1609 Attention: Craig Rowe Email: craig@clearrisk.com (b)if to Client at: Street City, State: Zip Code: Attention: Email: Phone: DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -13 - Any notice or other document if delivered shall be deemed to have been received by and given to the addressee on the date of delivery, and if given by email shall be deemed to have been received by and given to the addressee on the next Business Day following the day of sending. Any Party may at any time give notice in writing to the others of any change of address for these purposes. In the event of actual or threatened postal interruption in Canada or the United States, no such notice shall be deemed to have been received until it has in fact been received by the Party for whom it is intended. 16.8 Email Notifications. From time to time, ClearRisk may use a third party application for data submission and such application provides email notifications to Customer related to Customer’s input of data into the ClearRisk Service. Customer is responsible for ensuring that Customer’s email address is accurate and complete and that such information remains current at all times during the Term. In order to ensure successful delivery of such email notifications, Customer is advised to add IP address 35.169.190.25 hostname infra-mail.formassembly.com or such other domains provided by ClearRisk to Customer’s safe senders list to prevent email messages from being moved to Customer’s junk or spam folder. ClearRisk is not liable for any damages whatsoever caused by or resulting from the unsuccessful delivery of email notifications to Customer as a result of email notifications being directed to spam or junk filters, incorrect email addresses, incorrect email addresses, or other acts or omissions of Customer. 16.9 Governing Law. This Agreement and all matters arising out of or relating to this Agreement, whether sounding in contract, tort, or statute, are governed by and construed in accordance with the laws of the State of North Carolina and the federal laws of the United States applicable therein, without giving effect to the conflict of laws provisions thereof to the extent such principles or rules would require or permit the laws of any jurisdiction other than the State of North Carolina to apply and each of the Parties hereby irrevocably attorns to the exclusive jurisdiction of the courts of such State. The application of the United Nations Convention on Contracts for the International Sale of Goods to this Agreement is expressly excluded and does not apply to this Agreement. 16.10 Severability. The invalidity or unenforceability of any provision or part of any provision of this Agreement shall not affect the validity or enforceability of any other provision or part thereof, and any such invalid or unenforceable provision or part thereof shall be deemed to be separate, severable and distinct, and no provision or part thereof shall be deemed dependent upon any other provision or part thereof unless expressly provided for herein. 16.11 Currency. All dollar amounts referred to herein refer to lawful money of the United States of America. 16.12 Enurement. This Agreement and everything contained herein shall enure to the benefit of and are binding upon each of the Parties hereto and their respective successors and permitted assigns. 16.13 Entire Agreement. This Agreement, including the schedules attached hereto or terms, agreements or documents referred to herein, is the entire agreement between the Parties made to date regarding the subject matter and supersedes any prior agreements or understandings between the Parties relating to its subject matter. No modification or variation of this Agreement shall be effective unless in writing signed by the Parties. Signature, Counterparts, and Delivery. This Agreement may be signed electronically, including through DocuSign and similar applications. This Agreement may be signed in any number of counterparts (including counterparts by scanned or electronic signature) and each counterpart will be deemed an original; taken together, all counterparts will be deemed to constitute one and the same instrument. Delivery of a printed counterpart (whether or not the counterpart was signed electronically) or electronic delivery (including by email transmission or transmission over an electronic signature platform) of an executed counterpart of this Agreement are each as valid, enforceable and binding as if the signatures were upon the same instrument and delivered in person. IN WITNESS WHEREOF the signature of a duly authorized director of each of ClearRisk and Client were hereunto affixed in accordance with their rules and regulations in that behalf contained, the day and year first before written. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 -14 - CLEAR RISK US CORP. <client> Name: Craig Rowe Name: Title: CEO Title: Date: Date: I have authority to bind the corporation. I have authority to bind the corporation. May 10 2024 DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 5/14/2024 HR Director Brenda Bartholomew -15 - ClearRisk’s Customer Referral Program ClearRisk’s referral program provides an avenue for ClearRisk customers to avail of scholarship funds that can be used towards any of the following: ●payment towards a ClearRisk project or invoice ●donation to a charity of choice ●professional organization or association fees ●flight, hotel and/or entrance fees to events and conferences ●other ideas as presented by Client Participation is simple: Client would connect ClearRisk’s Customer Success team with the interested party and ClearRisk would handle everything else. If the organization adopted ClearRisk’s solutions and came onboard, Client would be provided $2,500 to be used accordingly. More information regarding ClearRisk’s Customer Referral Program can be found here: https://products.clearrisk.com/customer-referral-landing-page/ DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 SCHEDULE A FEE SCHEDULE Notes: 1.Professional Services will not commence until year-1 invoice is paid in full. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 SCHEDULE B INITIAL STATEMENT OF WORK DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 ClearRisk/Orange County ATTN: Melissa Tegeder STATEMENT OF WORK DATE: May 6th, 2024 DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 1 1.0 Document History Version Date Author Comment / Change 1.0 2024-04-30 Paul MacKinnon Draft 2.0 Scope/Objective The objective of this SOW is for ClearRisk to provide the implementation of their standard SaaS platform to Orange County. ClearRisk will provide: ● Standard ClearRisk package and user deployment ● Employee/HR System - One-way Data Feed (Employee/HR System to ClearRisk) ● Department Data Upload ● Webform Configuration - Incident Intake Form ● Training Sessions & Self-Guided Training Materials The acceptance criteria for each project deliverable (Items 4.0 to 11.0) is outlined in Appendix A. 3.0 Scope Limitations Any deviations from this SOW is considered out-of-scope and subject to the Change Request process as defined in Section “Change Management” Deliverable Definitions DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 2 4.0 Standard ClearRisk Package and User Deployment 4.1 ClearRisk Modules ClearRisk’s standard set of modules will be deployed to Orange County, where functionality per-module is not subject to change as part of the implementation, functionality not specifically listed below is not included in the implementation, and only ClearRisk’s standard fields/data points will be implemented. See below for list of modules and their functionality below: ClearRisk Module Standard Functionality Event ●Create Event Records ●Relate multiple Claims/Incidents to event Incidents/Claims ●Logging Incident/Claim information, including litigation ●Root Cause Analysis (Cause/Event Type/Incident Type/Incident Sub- Type) ●Follow-up and Correction actions (Incidents Only) ●Add Involved Person(s) information (Information driven from Contacts module) ●Add Involved Organization(s) information (Information driven from Organizations module) ●Add Involved Asset(s) information ●Add Financials (Reserves, Payments, Recoveries) and sub categorize by transaction owner and transaction type (Expense or Indemnity). Contacts ●Ability to log third party (Standard record type) contacts such as claimants and vendor contacts. ●Ability to log employee (Employee record type) information. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 3 Organizations ●Ability to log organizations such as adjusters, legal council, brokers, insureds. Assets ●This module is divided into five subsections (record types): ❖Properties ❖Buildings ❖Vehicles ❖Equipment ❖Mobile Equipment ●Building Values (contents, equipment, building value, income) will roll-up to related property COPE ●Ability to create stand-alone COPE records that relate to Building records Policies ●Create individual Policy Sections within Policy records ●Log policy subscriber (including share and commission percent) information ●Claims analysis per policy (Total Incurred, Reserved, Paid, Recovered) ●Link individual policies to insurance programs ●Functionality will not allow interconnectivity of policy limits (i.e policy towers) Insurance Policies ●Aggregating of deductibles, premiums and limits from all attached policies ●Claim analysis per program (Total Incurred, Reserved, Paid, Recovered, and Aggregate Remaining) Reports & Dashboards ●Ability to create, edit, and delete reports & dashboards (if license/access allows) Misc. Features ●Ability to add Tasks, Notes, Files to records (if license/access allows) DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 4 ● Send email from records 4.2 User Deployment User access will be created based on ClearRisk’s standard offering. See below: Claims User - Full module access, full reports/dashboard access ● Total User Count: 2 Licenses/Users 4.3 DKIM, DMARC, and SPF Configuration Implementation of security settings DKIM, DMARC & SPF to enable email notifications sent from both the ClearRisk system and webforms to properly display the customer’s email domain and increase likelihood of recipient receiving the email notification(s). While these configurations may prove beneficial to the workflow of Orange County, we advise that the city should seek approval from their IT team to ensure it aligns with their policies and procedures. High-level activities include: 4.4 Outlook Plugin - Provision of Documentation Users with ClearRisk licenses/logins can avail of the outlook plug -in used to easily attach inbound emails to records within the ClearRisk system. This plug -in is not managed or supported by ClearRisk (it was created by Salesforce) meaning configuration will primarily be done by Orange County. The purpose of this deliverable is for ClearRisk to provide setup documentation for the plugin. It is the responsibility of the Orange County team to work with their IT team to get the plugin properly configured. 4.5 Data & File Storage Initial storage provided within Orange County account: Data Storage (text records such as claims and properties) DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 5 ▪ 10.7 GB text data (space for ≈ 5,500,000 claim records, for example.) o Additional text data storage can be added at any time for an additional cost File Storage (allocation for file attachments such as pictures, PDF, etc.) ▪ 100 GB file storage ▪ This storage represents notes and file attachments stored within ClearRisk o Additional file data storage can be added at any time for an additional cost 4.6 Data Residency Orange County’s ClearRisk instance will be hosted on a US -based Salesforce server. On request, ClearRisk can provide additional information. 4.8 SSO Configuration ClearRisk will be configuring SSO with Azure AD or DUO for Orange County’s ClearRisk user group (Admin/Claims Users Only). See details below: ● Orange County’s IT team will provide ClearRisk with Certificate XML file (and other identity provider information if required for configuration) to ClearRisk. ● Federation ID for users will be the user’s email address ● Orange County’s IT resources will be available for troubleshooting if required. 5.0 One-way Data Feed (Employee/HR System to ClearRisk) The configuration of a set of processes that allows your employee/hr system to supply their CSV-formatted report to a ClearRisk-managed SFTP site. ClearRisk’s automation will retrieve the employee information provided periodically by DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 6 Orange County (via SFTP site) and create/update existing employee records within the ClearRisk system. High-level activities include: ● SFTP Configuration ● Mapping of Employee roster to ClearRisk System ● Data Automation (to create/update existing employee records) The integration will be limited to the data column headers from Appendix B Tab “Employee Roster Integration” and will use the Employee Number column as the unique identifier when matching or creating records. See Appendix D for workflow diagrams that include how integration will operate, and Appendix C for process diagrams that include ClearRisk’s general process for configuring integrations. 5.0 Data Migration Several types of data will be provided to ClearRisk by Orange County for manipulation and insertion into the ClearRisk system based on ClearRisk best practices. Data will be provided via Orange County completing ClearRisk data migration templates, or ClearRisk will manually manipulate Orange County existing data. See list of data types below as well as if a reference data sheet will be manipulated or ClearRisk’s data migration templates will be used: Data to be provided via ClearRisk migration templates ● Departments The data provided to ClearRisk by Orange County will be limited to that contained in the column header samples in Appendix B Tab “Data Migration” as well as the record amounts listed below. See below for list: Data Type Excel Sheet Tab (Appendix B) Records DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 7 Claims N/A N/A Claim Financials N/A N/A Claim Notes N/A N/A Claim Files N/A N/A Policies N/A N/A Properties/Buildings N/A N/A Vehicles N/A N/A Departments Data Migration 57 Contacts/Employees N/A N/A Organizations/Vendors N/A N/A Certificates N/A N/A Contracts N/A N/A The data migration will be executed based on ClearRisk best practices meaning provided data will be manipulated to fit into ClearRisk’s standard modules and fields. ClearRisk staff will endeavor to map the fields defined in the Data Migration tab of Appendix B into the ClearRisk dat a model. Fields that are not able to be directly mapped will be reviewed with the CUSTOMER for possible alternative options, but are not guaranteed to be included in the final configuration. High-level activities for the data migration include: ●SFTP creation for data transmission ●Data evaluation & mapping ●Data migration execution ●Migration UAT See Appendix C for process diagrams including ClearRisk’s general process for data migration. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 8 6.0 Webform Configuration - Incident Intake Form ClearRisk will be implementing an incident intake form based on ClearRisk’s standard system and webform implementation practices. This form will be used to intake all incident types in a single format (meaning the form or information collected will not vary based on the type of incident) & will automatically insert incident records into the ClearRisk system upon successful submission. This form will not replace Orange County’s incident processing and investigation workflow. The purpose of this form is for the employee/supervisor to access the form after the proper investigation/report forms are complete, fill out information, then attach the completed. incident & investigation forms. High-level activities for this deliverable include: ● Review of current forms/incident reporting framework ● Configuration of form mock-up ● Configuration of form iteration #1 ● Configuration of form iteration #2 ● Form UAT ClearRisk will be implementing their standard incident form, meaning sections will be implemented which will only include fields/data-points that exist in the ClearRisk system. See below: Form Section Section Description Reporter Details ● Collect information about the person submitting the webform ● Includes contact information & address ● If form is exclusive to employee submissions, employee number/email will be made mandatory or “employee search” field may be implemented. Incident Details ● Collect general details of the incident DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 9 (who, what, when, where), incident type. ● Large text box field “Incident Description” for detailed account of incident. Involved Person(s) Details ● Collect information about third parties involved (employees, witnesses, contractors, etc). Involved Asset(s) Details ● Collect information about organization assets (fleet, buildings, equipment, etc) involved. Corrective Actions ● Limit to the following fields: ➔ Action Taken (Text) ➔ Additional Notes (Text) ➔ Corrective Action Taken (Pick- list) ➔ Areas for Correction Action (Pick-list) Files/Attachments ● Ability to add up to 10 files/attachments ● 25 MB per file size limit, a 35 MB total file size limit for submission. See Appendix D for workflow diagrams that include how incident submission will occur via the claim intake form, and Appendix C for process diagrams that include ClearRisk’s general process for configuring incident intake webforms. 6.1 Webform Branding While optional, Orange County will be able to provide high definition logo and branding materials that will be consulted when configuring the webform. If no materials are provided form branding will be configured at ClearRisk’s discretion. 6.2 Help Text & Verbiage DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 10 Orange County will be able to provide text that will live on the body of the webform, which usually includes but is not limited to: ●Hyperlink URL to other pages/documents ●Form Instructions ●Disclaimer for submission (information collection) ●“Thank You” message that appears after form submission is completed 6.3 Notifications Each webform is able to send email notifications: ●Upon hitting submit, a static list of up to 10 email addresses (will not change based on incident/claim type) can be sent an email containing all information from the webform submission ●The notification will not contain the ClearRisk claim number, but will contain all other information submitted on the webform. 8.0 Training Sessions & Self-Guided Training Materials ClearRisk will offer both live training sessions and a library of knowledge base/self-guided training materials. 8.1 Live Training sessions ClearRisk will be providing two (2) online training sessions that will be facilitated via Zoom. These sessions will be recorded and sent to Orange County and follow a standard agenda meaning topics will be covered in a rigid order across training sessions. 8.2 Self-Guided Training Materials ClearRisk will provide their library of self-guided training documents (pdf format & video). Topics are broken down per-subject/module and at times contain links to small video aids. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 11 9.0 Project Controls 9.1 Project Meetings Both project teams will engage in 30-minute weekly status update meetings for the duration of the project. Agenda includes: ● Prior meeting’s takeaway review ● Schedule status ● Required work/materials from both Orange County and ClearRisk team members (i.e meeting takeaways to be actioned on and their due date) ● Issue log item discussion (if applicable) 9.2 Inspection & Acceptance Orange County shall inspect all Deliverables that ClearRisk develops under this SOW. ClearRisk shall inform Orange County of the due dates for all inspections and provide materials of the Deliverable subject to inspection at least one week before the inspection due date unless otherwise specified. ClearRisk will provide deliverable acceptance forms that once returned will signify deliverable sign-off/completion. The CUSTOMER completing its inspection and acceptance by the agreed due dates is critical for the overall project timeline. See Appendix G for sample form. 9.3 Change Management The project’s change management process may be invoked in the event that customer requirements change from what is outlined in the SOW during the project. Changes requested to the project tasks, milestones, or schedule of a project (if substantial) will be formally tracked through ClearRisk’s change request process. Each change request form will document the following: ● Description & justification of change ● Cost impact of change ● Schedule impact of change DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 12 ● Required resources to facilitate change If ClearRisk approves the change, the form will be sent to the customer to review. By signing and sending back the change request form the following actions will be triggered in sequential order: 1. Invoice will be sent to Orange County for amount listed on the change request 2. Customer will send payment to ClearRisk 3. Once payment is received project task, milestones, and schedule changes will be made 4. New schedule will be provided to the customer In the event the change is denied, ClearRisk will communicate the status of the change to Orange County, close the change request, and archive the document(s). See appendix E for an example of ClearRisk’s change request form 10.0 Quality Management ClearRisk utilizes various quality methods to verify deliverables and provide our customers with the materials to aid in and the ability to review and accept deliverables. 10.1 Data Migration Quality Management 10.1.1 User Acceptance Testing (Data Migration) Once final data migration has been completed, the Orange County ClearRisk user(s) (can be a single user or many) will complete the “Data Migration” section of the user acceptance testing document and return it to ClearRisk. The user(s) DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 13 will be required to sign off and date items that they deem complete and items that need fixing/reupload (with description & evidence of issue). User acceptance testing (UAT) will not cover items outside of project scope. 10.1.2 Migration Map If ClearRisk’s data migration templates are not being used for all data-sets, a migration map (excel format) will be created per -upload and provided to Orange County by ClearRisk. This map will include the following: ● Module & field source column is being mapped to ● Pick-list option mappings per-field if applicable ● Fields that will be aggregated to a ‘Note’ ● Fields that will not be migrated to ClearRisk This map will be used by Orange County when validating the data and completing data migration UAT, and is considered the source of truth for the project’s data migration. 10.1.3 Data Validation - Report Creation (Record Upload) ClearRisk will create one or multiple reports to display the data as closely formatted to the source (i.e provided data for upload) data as possible. All upload reports will be aggregated to a single folder that the Orange County users will have access to. Only ClearRisk users will be able to review these reports. If individuals outside of the ClearRisk user group are required to validate the reports, the ClearRisk users can export each report as Excel/CSV format and send to other parties. These reports will exclude ‘Notes’ and ‘Files/Attachments’. 10.1.4 Data Validation - Record Spot-Checking DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 14 ClearRisk would complete this as part of an internal validation process (not listed in SOW). This process would be handled completely by Orange County users as part of Data Migration User Acceptance Testing (UAT). 10.2 Application Quality Management 10.2.1 User Acceptance Testing (Application) Orange County user(s) (can be a single user on behalf of the entire team or many users) will be required to carry out user acceptance testing (UAT) on their ClearRisk instance. UAT is comprised of multiple lists of tasks related to the following sections: ● Module Checklist (Mandatory) ● Functionality Checklist (Mandatory) ● Webform Checklist (Only applicable if webform implementation is a part of the project) Once completed the Orange County users will send the document back to the ClearRisk project team for review. See appendix F for an example of how the UAT sheet is formatted. User acceptance testing (UAT) will not cover items outside of project scope. 11.0 Implementation Timeline Orange County’s account implementation commences once ClearRisk receives the executed contract and invoice payment. A project kickoff session is scheduled between ClearRisk and Orange County before the commencement of the implementation. Implementations with a similar scope tend to run 16* weeks, but may vary based on the following criteria: ● Complexity in data that results in increased manipulation and upload time DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 15 ●Errors/incompatibility between data populated in templates and guidelines set out by ClearRisk ●Customer responsiveness to questions on data templates, functionality, form edits, and workflow requirements ●Complexity of workflow requirements (users, webform, system integrations, etc.) Within 2 weeks of the payment being received, ClearRisk will provide the Orange County project team with a project start date and proposed schedule of work (which will include final duration). 11.1 Timeline to Claim/Incident Entry Upon kick-off the schedule and work to be executed will be prioritized to enable the ORANGE COUNTY ClearRisk users to enter new claims/incidents into the ClearRisk system by July 1 2024. Prerequisite work to accomplish this is limited to: ●Creation of ORANGE COUNTY’s ClearRisk Account ●Provisioning of all required modules (see 4.1) to ORANGE COUNTY ClearRisk users. ●Provisioning of ClearRisk Training Sessions (2 one-hour sessions for Phase 1) ●Upload of ORANGE COUNTY Department Data This goal can only be met if payment is received by June 1, 2024. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 CERTIFICATE OF INSURANCE This certificate is issued as a matter of information only and confers no rights upon the certificate holder. This certificate does not amend, extend or alter the coverage afforded by the policies below. COMPANIES AFFORDING COVERAGE COVERAGES CERTIFICATE HOLDER CANCELLATION CSIO CERT (6/00) BROKER BROKER'S CLIENT ID: INSURED'S FULL NAME AND MAILING ADDRESS CO LTRTYPE OF INSURANCE POLICY NUMBER POLICY EFFECTIVE DAT E (YY/MM/DD) POLICY EXPIRATION DAT E (YY/MM/DD) LIMITS OF LIABILITY (Canadian dollars unless indicated otherwise) COMMERCIAL GENERAL LIABILITY AUT OMOBILE LIABILITY EXCESS LIABILITY OTHER LIABILITY (SPECIFY) ADDIT IONAL INSURED DESCRIPTION OF OPERATIONS/LOCATIONS/AUTOMOBILES/SPECIAL ITEMS SIGNATURE OF AUTHORIZED REPRESENTATIVE PRINT NAME INCLUDING POSITION HELD FAX NUMBER EMAIL ADDRESS COMPANY DAT E This is to certify that the policies of insurance listed below have been issued to the insured named above for the policy period indicated, notwithstanding any requirement, term or condition of any contract or other document with respect to which this certificate may be issued or may pertain. The insurance afforded by the policies described herein is subject to all the terms, exclusions and conditions of such policies.LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. COMPANY A COMPANYB COMPANYC COMPANYD CLAIMS MADE OR OCCURRENCE PRODUCTS AND / OR COMPLETED OPERATIONS EMPLOYER'S LIABILITY CROSS LIABILITY TENANT'S LEGAL LIABILITY NON-OWNED HIRED POLLUTION LIABILITY EXTENSION DESCRIBED AUTOMOBILES ALL OWNED AUTOS LEASED AUTOMOBILES ** ALL AUTOMOBILES LEASED IN EXCESS OF 30 DAYS WHERE THE INSURED IS REQUIRED TO PROVIDE INSURANCE UMBRELLA FORM OTHER THAN UMBRELLA FORM (Specify)___________________________________________________ EACH OCCURRENCE GENERAL AGGREGATE PRODUCTS - COMP/OP AGG PERSONAL INJURY TENANT'S LEGAL LIABILITY MED EXP (Any one person) NON-OWNED AUTO OPTIONAL POLLUTION LIABILITY EXTENSION (Per Occurrence) (Aggregate) BODILY INJURY PROPERTY DAMAGE COMBINED BODILY INJURY(Per person) BODILY INJURY(Per accident) PROPERTY DAMAGE EACH OCCURRENCE AGGREGATE $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ $ DAT E (YY/MM/DD) 24/04/25 Cal LeGrow Insurance Ltd. 189 Higgins Line St.John's NL A1B 4N4 CLEAINC-01 Travelers Insurance Company ClearRisk Inc.&ClearRisk US Corp. P.O.Box 21097 St.John's NL A1A 5B2 5,000,000 X X X X X A 24/02/16 25/02/16TRV0347036 5,000,000 5,000,000 5,000,000 1,000,000 10,000 X 2,000,000 X A TRV0347036 24/02/16 25/02/16 5,000,000 Cyber Liability Errors &Omissions Liability A TRV0347036 24/02/16 25/02/16 Each Occurrence Aggregate $5,000,000 $5,000,000 Orange County,its Officers,Agents and Employees 300 West Tryon Street P.O Box 8181 Hillsborough NC 27278 All operations usual to the business of the Named Insured.It is hereby understood and agreed that the Certificate Holder is added as an additional insured with respect to the legal liability arising from both the operations of the Named Insured and as required by the contract.Additional insured is not added to any form of automobile insurance. See Attached... Orange County 300 West Tryon Street P.O Box 8181 Hillsborough NC 27278 SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF,THE ISSUING COMPANY WILL ENDEAVOR TO MAIL 30 DAYS WRITTEN NOTICE TO THE CERTIFICATE HOLDER NAMED TO THE LEFT,BUT FAILURE TO MAIL SUCH NOTICE SHALL IMPOSE NO OBLIGATION OR LIABILITY OF ANY KIND UPON THE COMPANY,ITS AGENTS OR REPRESENTATIVES. Olanike Odoemenah,Commercial Service Rep. 709-576-1238 oodoemenah@callegrow.com Cal LeGrow Insurance Ltd.24/04/25 DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5 DESCRIPTIONS Continued. REMARKS: Operations of the insured include Web-Based SaaS software for claims and risk management. Orange County,its Officers,Agents and Employees are Listed as Additional Insured ONLY with Respect to the Legal Liability of the Operations of the Named Insured. DocuSign Envelope ID: BD441C19-1E7C-4FDE-8321-A4585AF240A5