Orange County NC Website
DocuSign Envelope ID:90A54439-23B9-40AF-8246-BFCAAEAA529D <br /> • Submittable employees may not store Personal Information on a personally owned device; unless <br /> such device has been authorized and secured by Submittable using an encryption mechanism <br /> appropriate to the level of sensitivity of information stored. <br /> • Submittable classifies Personal Information to allow for appropriate access restrictions. <br /> • Submittable has implemented an anti-virus solution that shall be kept up to date to protect <br /> against viruses and other malicious code. <br /> • Submittable maintains a record of security breaches with a description of the breach, the time <br /> period, the consequences of the breach, the name of the reporter, and to whom the breach was <br /> reported, and the procedure for recovering data. <br /> • TRANSMISSION CONTROLS <br /> • All databases are restricted to use private (internal) IP addresses only and can only be accessed by <br /> connecting to Submittable's virtual private cloud (VPC) network. <br /> • Customers and End Users access Submittable accounts over HTTPS. <br /> • DATA BACKUPS <br /> • All production databases are housed in Amazon Web Services RDS (Relational Database Service). <br /> • Automated daily backups are enabled on all database instances. <br /> • Encryption is enabled on all databases. <br /> • Retention time for instances housing production related databases is set to the maximum <br /> allowable. <br /> • Only database administrators have access to initiate backups or restores. <br /> • Only database administrators may modify backup or restoration configurations. <br /> • Submittable retains its security documents pursuant to its retention requirements after they are <br /> no longer in effect. <br /> • DATA SEGREGATION <br /> • All data is stored in a multi-tenant relational database with logical separations. <br /> • Personal Information is separated using foreign keys and application logic. <br /> Submittable Customer Terms of Service vl.1—Exhibit B,Appendix B Page 2 of 2 <br />