泭
SecureNow Services Additional Terms
1. Services. 51勛圖厙踏梜埳, itself and through its Affiliates and Service Providers, will provide to Client the services described herein (the SecureNow Services). The SecureNow Services provide an automated and scalable system to help protect against cyberattacks and aid in cyber fraud detection. 51勛圖厙踏梜埳 may determine in its discretion to provide the SecureNow Services only in connection with other specified 51勛圖厙踏梜埳 services. User(s) means the end customer(s) of Client who have been approved for use of the applicable digital banking service pursuant to procedures agreed to between 51勛圖厙踏梜埳 and Client.
(a) Behavior Analytics Services. If elected by Client, 51勛圖厙踏梜埳 will provide behavior analytics services (Behavior Analytics Services) to aid in the real-time detection of anomalous and potentially malicious User behaviors during certain User events within the 51勛圖厙踏梜埳 online banking service (e.g., User login, User changing email address, etc.). 51勛圖厙踏梜埳 may terminate the Behavior Analytics Services upon notice to Client if 51勛圖厙踏梜埳's agreements with its Service Provider(s) for Behavior Analytics Services terminate. Prior to such termination, 51勛圖厙踏梜埳 will use commercially reasonable efforts to replace such Service Provider(s).
(b) Login Defense Services. If elected by Client, 51勛圖厙踏梜埳 will provide User login defense services (Login Defense Services) to aid real-time detection of cyberattacks and evasive actions during the User login process, as well as recognition of User endpoints.
(c) Mobile Authentication Digital Banking Authentication Services. If elected by Client, 51勛圖厙踏梜埳 will provide digital banking authentication services leveraging the Users mobile phone without use of passwords (Mobile Authentication - Digital Banking Authentication Services).
(d) Out-of-Band Authentication Services. If elected by Client, 51勛圖厙踏梜埳 shall provide a telephone or SMS mobile phone text message communications channel to Clients Users on behalf of Client, to assist in authenticating such Users (Out-of-Band Authentication Services). 51勛圖厙踏梜埳 shall have the right to terminate performance of the Out-of-Band Authentication Services upon twelve (12) months prior written notice to Client.
(e) Out-of-Wallet Verification Services. If elected by Client, 51勛圖厙踏梜埳 will provide out of wallet verification services (Out-of-Wallet Services) to assist in User verification and authentication by presenting certain multiple choice knowledge-based authentication (KBA) questions to the User based on the Users public data history.
(f) SecureNow Data Feed Services. If elected by Client, 51勛圖厙踏梜埳 will make available to Client certain SecureNow input and risk decisioning data (Data Feed Services) gathered from the Behavior Analytics Services and Login Defense Services utilized by Client (and to the extent such Services are elected by Client in this Schedule). Client shall be solely responsible for its use of the data provided by the Data Feed Services, and 51勛圖厙踏梜埳 shall have no obligation to provide support after Client successfully accesses the data provided by the Data Feed Services, including without limitation, support related to Clients analysis of such data.
2. Performance.
(a) Hours. 51勛圖厙踏梜埳 will use reasonable efforts to make the SecureNow Services available to Client 24 hours a day, 7 days a week, subject to scheduled maintenance, scheduled downtime, and causes beyond the reasonable control of 51勛圖厙踏梜埳. 51勛圖厙踏梜埳 shall have no obligation to address or support: issues caused by Client alterations or modifications to the SecureNow Services; services that are not currently supported; SecureNow Services problems caused by Clients negligence, abuse, or misapplication; use of SecureNow Services other than as specified herein or the SecureNow Services documentation; or SecureNow Services problems caused by Clients failure to perform its responsibilities, including as listed below.
(b) Service Providers. The SecureNow Services provide various combinations of cyber protections through the integration of risk component services provided by 51勛圖厙踏梜埳 and one or more third party service providers (each a Service Provider). 51勛圖厙踏梜埳 has the exclusive right to determine the composition of Service Providers integrated within the SecureNow Services, including any replacement or addition of Service Providers used in conjunction with this SecureNow Services. Client grants 51勛圖厙踏梜埳 permission to pass data to Service Providers in order to deliver SecureNow Services and to represent data in user-friendly form in any Service Provider management interfaces used by the Client or 51勛圖厙踏梜埳 to support services. 51勛圖厙踏梜埳 shall remain liable for the performance of such Service Providers and shall provide Client with no less than 90 days notice if 51勛圖厙踏梜埳 changes Service Providers in a manner that necessitates material changes to Clients implementation. 51勛圖厙踏梜埳 may terminate the SecureNow Services, or applicable portions thereof, upon notice to Client if 51勛圖厙踏梜埳眄s agreements with its Service Provider(s) terminate. Prior to such termination, 51勛圖厙踏梜埳 will use commercially reasonable efforts to replace such third party Service Provider(s).
(c) Support. Client is responsible for first tier support to its Users. 51勛圖厙踏梜埳 will log an initial technical support inquiry from Client and initiate the troubleshooting process. Client agrees to provide all User technical support and 51勛圖厙踏梜埳 will provide second level technical support to Clients support representatives during 51勛圖厙踏梜埳眄s standard operating hours, unless otherwise agreed upon by the parties. Technical support, as referred to herein, means 51勛圖厙踏梜埳 will take an initial technical support inquiry from Client and initiate the troubleshooting process. 51勛圖厙踏梜埳 will use commercially reasonable efforts to determine the source of support issues and to remedy the issues. Unless otherwise agreed in writing, 51勛圖厙踏梜埳 will not provide onsite support.
(d) Third Party Factors. Client acknowledges that the SecureNow Services involve the use of non-confidential Internet, telephone and wireless telecommunication networks to potentially transmit and/or receive information from Client's Users. Client acknowledges that 51勛圖厙踏梜埳's performance of the SecureNow Services is dependent on the facilities, networks, security and connectivity of third party telecommunications and network service providers, governmental entities and other third parties (collectively, the Third Party Factors). Client acknowledges that the performance of the SecureNow Services will be affected by such Third Party Factors and that Third Party Factors are outside 51勛圖厙踏梜埳's control. FISERV WILL HAVE NO LIABILITY FOR ANY REDUCTION, INTERRUPTION, IMPAIRMENT, TERMINATION OR SUSPENSION OF THE SECURENOW SERVICES TO THE EXTENT CAUSED BY FACTORS OUTSIDE FISERV'S CONTROL.
(e) No Guarantee. Client acknowledges and agrees that (i) 51勛圖厙踏梜埳 cannot guarantee that Clients use of SecureNow Services will prevent all cyberattacks or detect all cyber fraud; and (ii) use of information technology carries inherent information security risks and information security cannot be guaranteed, generally. SecureNow Services are only a component of, and should not be considered to be a replacement of, or substitute for, Clients own enterprise data protection and fraud prevention strategy.
3. Client Responsibilities.
(a) Client must ensure that each Client User has consented to share data with 51勛圖厙踏梜埳 and its Service Providers for the purposes of detecting and preventing fraud. Client must ensure that the Client Users agree to the following (or substantively the same clause using corresponding definitions from Clients terms with Client Users), except as 51勛圖厙踏梜埳 and Client otherwise agree in writing:
Client may share certain personal information and device-identifying technical data about User and Users devices with third party service providers who will compare and add device data and fraud data from and about User and Users devices to a database of similar device and fraud information in order to provide fraud management and prevention services and identify and block access to the applicable service or Web site by devices associated with fraudulent or abusive activity. Such information may be used by Client and its third party service providers to provide similar fraud management and prevention services for services or Web sites not provided by Client.
(b) From time to time, Client may be required to provide 51勛圖厙踏梜埳 with a reasonable and acceptable number of production test accounts that have all available account types and functions represented in each one for resolution of support and maintenance related issues.
(c) Fraud Detection and Investigation.
(i) Client acknowledges that data gathered from confirmed cases will be utilized to detect fraud for other 51勛圖厙踏梜埳 clients. Client grants 51勛圖厙踏梜埳 permission to use such data to further the detection and prevention of cyberattacks and fraud; however, no proprietary consumer information is shared or viewable by other 51勛圖厙踏梜埳 clients, other than reasonably necessary information, such as User name.
(ii) Client is responsible to provide an operations lead contact in order to collaborate with SecureNow Services security operations leadership for ongoing operational, incident, or forensics investigations. Client will designate personnel with the skills to review and assist in research when necessary, and Client will notify 51勛圖厙踏梜埳 of such personnels contact information (and any changes thereto) for the purpose of 51勛圖厙踏梜埳 contacting Client with regard to alerts, cases and other matters related to the SecureNow Services.
(iii) Client will notify 51勛圖厙踏梜埳 within 24 hours of fraud cases originating from its digital banking services that were not detected and blocked by SecureNow Services.
(d) Clients access and use of the Behavior Analytics Services are subject to the following additional terms and conditions (the BAS Terms and Conditions):
(i) Guardian. 51勛圖厙踏梜埳, itself and through its third party subcontractor Guardian Analytics Inc. (Guardian) (or its successor) provides the Behavior Analytics Services. Guardian shall be an express third-party beneficiary of these BAS Terms and Conditions. Notwithstanding anything to the contrary in the Agreement, (a) Client hereby consents to Guardians use of a third party data center provider in its provision of the Behavior Analytics Services; and (b) Client acknowledges and agrees that Guardian and its subcontractors shall be under no obligation to conduct drug testing on their respective personnel involved in the provision of the Behavior Analytics Services.
(ii) Use. Client is responsible for all activities conducted under its User logins on the Behavior Analytics Services. Client shall use the Behavior Analytics Services solely for its internal business purposes for its intended use and in compliance with applicable law and shall not:
A. send or store infringing or unlawful material, or send or store viruses, worms, time bombs, Trojan horses and other harmful or malicious code, files, scripts, agents or programs;
B. attempt to gain unauthorized access to, or disrupt the integrity or performance of, the Behavior Analytics Services or the data contained therein;
C. modify, copy, or create derivative works based on the Behavior Analytics Services;
D. reverse engineer, translate, disassemble, decompile or otherwise access or download the underlying software, source code or algorithms of the Behavior Analytics Services or cause or permit others to do so;
E. use, or permit Users to sublicense or use, the Behavior Analytics Services for the purpose of building a competitive product or service or copying its features, functions, graphics or user interface, or for commercial time-sharing, rental, outsourcing, or service bureau use;
F. make any statement or suggestion, or use Guardians logos and trademarks in any manner, that dilutes, degrades, disparages or otherwise reflects adversely on Guardian or its business, products or services;
G. permit access to the Behavior Analytics Services by any third party; and
H. remove or obscure any title, trademark, copyright and/or restricted rights notices or labels from the Behavior Analytics Services or documentation.
(iii) Prior to authorizing access to the Behavior Analytics Services by Client personnel, Client shall conduct a check against the U.S. Treasurys Office of Foreign Assets Controls (OFAC), Specially Designated Nationals and Blocked Persons (SDN) database, and Client personnel appearing in such database shall not be permitted to access the Behavior Analytics Services.
(iv) Client hereby grants Guardian and 51勛圖厙踏梜埳 a royalty-free, fully paid-up, nonexclusive, perpetual, irrevocable, worldwide, transferrable (only to a successor in interest by way of merger, reorganization or sale of all or substantially all assets or equity), sub-licensable license to use, copy, modify or distribute, including by incorporating into the Behavior Analytics Services, any suggestions, enhancement requests, recommendations or other feedback provided by Client or its Users relating to the Behavior Analytics Services.
(v) Client agrees that Guardian may send it information regarding new Guardian products and services and other marketing communications unless Client notifies Guardian it wishes to opt out of receiving such communications. Client understands that even if it so opts out, it nevertheless will continue receiving system messages and other communications relating to the operation of the Behavior Analytics Services.
(vi) Client shall indemnify 51勛圖厙踏梜埳 and Guardian for any loss arising from Client's breach of BAS Terms and Conditions. Client shall bring all claims regarding the Behavior Analytics Services and Guardian's provision thereof solely against 51勛圖厙踏梜埳 and shall not bring any claims regarding the Behavior Analytics Services against Guardian
(vii) Purchases by Client of the Behavior Analytics Services are non-cancelable, and fees are non-refundable. Client agrees it may be contacted, and its access to the Behavior Analytics Services may be suspended, by 51勛圖厙踏梜埳 and/or Guardian for any failure to pay amounts due or violation of these BAS Terms and Conditions.
(viii) Client grants 51勛圖厙踏梜埳 and Guardian a worldwide, royalty-free, non-exclusive, right and license to use any and all Non-Identifiable Activity Data for purposes including but not limited to 51勛圖厙踏梜埳 or Guardians analytic, statistical, security and aggregation in order to make 51勛圖厙踏梜埳眄s or Guardians products and services available to its customers. Client represents and warrants to 51勛圖厙踏梜埳 and Guardian that it has the right to grant the foregoing licenses in the Non-Identifiable Activity Data. As used herein, Non Identifiable Activity Data means all records of banking activity submitted by Clients customers to the Behavior Analytics Services (Activity Data) that is devoid of any characteristic that might connect the Activity Data to Client or Clients customer including but not limited to data that (a) identifies an individual (by name, signature, address, telephone number, account number or other unique identifier) or (b) that can be used to authenticate that individual (including, without limitation, passwords or PINs, biometric data, unique identification numbers, answers to security questions, or other personal identifiers).
(ix) Offshore employees and Contractors of Guardian may perform certain activities related to the Behavior Analytics Services, such as software coding and code testing; quality assurance activities; and production, operational and engineering support, which may include read-only access to Client data. As used herein, Contractors means individual contractors whom: (a) Guardian retains on a staff augmentation basis; and (b) are employed by third party staff augmentation firms, but whom are subject to all screening and similar procedures to which Guardians employees are subject.
(x) Client is responsible to ensure that credit card numbers cannot be included as account identifiers for User accounts supported by Behavior Analytics Services.
4. Additional Terms.
(a) User Data. Client and Users may be required to share with 51勛圖厙踏梜埳 certain data, including without limitation: (i) the User's, name, e-mail address, zip or postal code; and (ii) account information (e.g., financial data, user identification, login and password and personal information (including without limitation birth date, IP address and social security number), as well as the ABA Routing and Transit Number that are specific to a User's account (collectively, User Data). Client hereby consents to 51勛圖厙踏梜埳眄s disclosure of the User Data to certain 51勛圖厙踏梜埳 Service Provider(s) solely in connection with the SecureNow Services and subject to the terms and conditions herein and the Agreement. Client acknowledges that such SecureNow Services are proprietary and confidential and shall be treated as 51勛圖厙踏梜埳 Information under the Agreement. Client grants to 51勛圖厙踏梜埳 and 51勛圖厙踏梜埳眄s applicable Service Providers a non-exclusive, non-transferable, except as provided herein, right to use, copy, store, modify and display the User Data solely to the extent necessary to provide the SecureNow Services pursuant to this Agreement. Client represents that it has obtained all necessary User agreements or consents as may be reasonably required to grant such license rights to 51勛圖厙踏梜埳 and its Service Providers.
(b) Permitted Use. The SecureNow Services will be only used for the purpose of verifying the identity of the User and will not be used, in whole or in part, as a basis for determining the eligibility of a User for credit, insurance or employment or to take adverse action, as defined in the Fair Credit Reporting Act or similar laws. Client will not copy or retain any authentication questions or the Users answers to such questions or use such questions for purposes other than identity verification and User authentication, except (i) as required by law and (ii) that Client shall be permitted to use and retain the pass/fail indication returned by the SecureNow Services along with any related explanatory information/codes for risk management or other internal purposes permitted by law. Client will not reverse engineer or create derivative works based on the identity verification and authentication elements of the SecureNow Services (or the technology used to provide such SecureNow Services).
(c) Access. Client acknowledges that access to the SecureNow Services shall be across public and private lines and that 51勛圖厙踏梜埳 has no control over such lines or the information available from non51勛圖厙踏梜埳 sources. 51勛圖厙踏梜埳 shall not be held responsible for any delays or missed delivery dates by a third party unless such third party is a subcontractor of 51勛圖厙踏梜埳.
(d) SMS Services. With respect to the SMS mobile phone text message communications (SMS Services) included as part of 51勛圖厙踏梜埳眄s provision of the SecureNow Services hereunder, Client shall not use, and shall not permit Clients Users, employees, agents, representatives and third party contractors (collectively, Client Users) to use the SMS Services to transmit or disseminate any messages that violate the terms of this Agreement or for any illegal, fraudulent, unauthorized purpose. The foregoing notwithstanding, Client is solely responsible for any and all activities that occur on its SMS Services account, including the actions of Client Users when using the SMS Services. Client agrees to immediately notify 51勛圖厙踏梜埳 of any unauthorized use of the SMS Services or any other breach of security known to Client and shall cooperate with 51勛圖厙踏梜埳, Service Providers and/or the relevant telecommunications carriers in investigations and other actions taken for suspected or known violations of this Agreement, including any incidents of spam by Client or any User.
(e) Market Adoption. Client agrees to assist 51勛圖厙踏梜埳 with certain marketing efforts associated with the SecureNow Services, as reasonably requested by 51勛圖厙踏梜埳 and mutually agreed to, which may include a press release announcing selection of the SecureNow Services, marketing the SecureNow Services to Clients customers, and serving as a reference contact, among other examples. In addition, Client agrees 51勛圖厙踏梜埳 may aggregate Clients non-personal user data and information relative to the use of the SecureNow Services by Users and their mobile devices with similar data from other 51勛圖厙踏梜埳 customers for the purposes of enhancing 51勛圖厙踏梜埳 products and adoption techniques.