Orange County NC Website
DocuSign Envelope ID:90A54439-23B9-40AF-8246-BFCAAEAA529D <br /> Report or another audit report that may compromise the security of Submittable's information <br /> technology environment or the confidentiality of any third-party confidential information, provided <br /> that such removal does not prevent Customer from understanding the substance of the Submittable <br /> Audit Report or another audit report. Submittable will make good faith, commercially reasonable <br /> efforts to promptly remediate: <br /> (a) any errors identified in a Submittable Audit Report that could reasonably be <br /> expected to have an adverse impact on Customer's use of the Services as set forth in the TOS; <br /> and <br /> (b) material deficiencies identified in a Submittable Audit Report. <br /> 13.3 The Parties agree that the audits described in the Standard Contractual Clauses shall be <br /> carried out in accordance with the following specifications: <br /> (a) upon Customer's reasonable request, and subject to the confidentiality obligations <br /> set forth in the TOS, Submittable shall make available to Customer (or Customer's <br /> independent, third-party auditor that is not a competitor of Submittable and that has signed <br /> nondisclosure agreement reasonably acceptable to Submittable) information regarding <br /> Submittable's compliance with the obligations set forth in this DPA; <br /> (b) following any notice by Submittable to Customer of an actual or reasonably <br /> suspected unauthorized disclosure of Personal Information, upon Customer's reasonable belief <br /> that Submittable is in breach of its obligations in respect of protection of Personal Information <br /> under this DPA, or if such audit is required by Customer's Supervisory Authority, Customer <br /> may contact Submittable in accordance with the "Notice" Section of this DPA to request an <br /> audit at Submittable's premises of the procedures relevant to the protection of Personal <br /> Information; <br /> (c) any such request shall occur no more than once annually, save in the event of an <br /> actual or reasonably suspected unauthorized access to Personal Information; <br /> (d) Such audit shall be at Customer's sole cost and expense; <br /> (e) before the commencement of any such on-site audit, Customer and Submittable <br /> shall mutually agree upon the scope, timing, and duration of the audit; and <br /> (f) Customer shall promptly notify Submittable with information regarding any non- <br /> compliance discovered during the course of an audit. <br /> 14. Warranties. <br /> 14.1 Submittable warrants and represents that: <br /> (a) its employees, Sub-processors, agents, and any other person or persons accessing <br /> Personal Information on its behalf are reliable and trustworthy and have received the required <br /> training on the Privacy and Data Protection Requirements relating to the Personal Information; <br /> (b) it and anyone operating on its behalf will Process the Personal Information in <br /> compliance with both the terms of this DPA and all applicable Privacy and Data Protection <br /> Requirements and other Laws, enactments, regulations, orders, standards, and other similar <br /> instruments; <br /> (c) it has no reason to believe that any Privacy and Data Protection Requirements <br /> prevent it from providing any of the TOS's contracted Services; <br /> (d) to the best of its knowledge, the Services are free of and do not contain any code <br /> or mechanism that collects information, bypasses Customer authentication and authorization <br /> controls or asserts control of any Customer network or system without Customer's prior written <br /> consent; <br /> Submittable Customer Terms of Service v1.1—Exhibit B Page 10 of 12 <br />