|
Orange Co Whitted Chiller September 08, 2025
<br />
<br /> Page 16 of 18 © 2025 Trane Technologies. All Rights Reserved.
<br />Confidential and Proprietary Information of Trane U.S. Inc.
<br />SECURITY ADDENDUM
<br />
<br />This Addendum shall be applicable to the sale, installation and use of Trane equipment and the sale and provision of Trane services.
<br />“Trane” shall mean Trane U.S. Inc. for sales and services in the United States, or Trane Canada ULC for sales and services in
<br />Canada.
<br />1. Definitions. All terms used in this Addendum shall have the meaning specified in the Agreement unless otherwise defined
<br />herein. For the purposes of this Addendum, the following terms are defined as follows:
<br />“Customer Data” means Customer account information as related to the Services only and does not include HVAC Machine
<br />Data or personal data. Trane does not require, nor shall Customer provide personal data to Trane under the Agreement. Such
<br />data is not required for Trane to provide its Equipment and/or Services to the Customer.
<br />“Equipment” shall have the meaning set forth in the Agreement.
<br />“HVAC Machine Data” means data generated and collected from the product or furnished service without manual entry. HVAC
<br />Machine Data is data relating to the physical measurements and operating conditions of a HVAC system, such as but not limited
<br />to, temperatures, humidity, pressure, HVAC equipment status. HVAC Machine Data does not include Personal Data and, for the
<br />purposes of this agreement, the names of users of Trane’s controls products or hosted applications shall not be Personal Data,
<br />if any such user chooses to use his/her name(s) in the created accounts within the controls product (e.g.,
<br />firstname.lastname@address.com). HVAC Machine Data may be used by Trane: (a) to provide better support services and/or
<br />products to users of its products and services; (b) to assess compliance with Trane terms and conditions; (c) for statistical or
<br />other analysis of the collective characteristics and behaviors of product and services users; (d) to backup user and other data
<br />or information and/or provide remote support and/or restoration; (e) to provide or undertake: engineering analysis; failure
<br />analysis; warranty analysis; energy analysis; predictive analysis; service analysis; product usage analysis; and/or other desirable
<br />analysis, including, but not limited to, histories or trends of any of the foregoing; and (f) to otherwise understand and respond to
<br />the needs of users of the product or furnished service. “Personal Data” means data and/or information that is owned or controlled
<br />by Customer, and that names or identifies, or is about a natural person, such as: (i) data that is explicitly defined as a regulated
<br />category of data under any data privacy laws applicable to Customer; (ii) non-public personal information (“NPI”) or personal
<br />information (“PI”), such as national identification number, passport number, social security number, social insurance number, or
<br />driver’s license number; (iii) health or medical information, such as insurance information, medical prognosis, diagnosis
<br />information, or genetic information; (iv) financial information, such as a policy number, credit card number, and/or bank account
<br />number; (v) personally identifying technical information (whether transmitted or stored in cookies, devices, or otherwise), such
<br />as IP address, MAC address, device identifier, International Mobile Equipment Identifier (“IMEI”), or advertising identifier; (vi)
<br />biometric information; and/or (vii) sensitive personal data, such as, race, religion, marital status, disability, gender, sexual
<br />orientation, geolocation, or mother’s maiden name.
<br />“Security Incident” shall refer to (i) a compromise of any network, system, application or data in which Customer Data has been
<br />accessed or acquired by an unauthorized third party; (ii) any situation where Trane reasonably suspects that such compromise
<br />may have occurred; or (iii) any actual or reasonably suspected unauthorized or illegal Processing, loss, use, disclosure or
<br />acquisition of or access to any Customer Data.
<br />“Services” shall have the meaning set forth in the Agreement.
<br />2. HVAC Machine Data; Access to Customer Extranet and Third Party Systems. If Customer grants Trane access to HVAC Machine
<br />Data via web portals or other non-public websites or extranet services on Customer’s or a third party’s website or system (each,
<br />an “Extranet”), Trane will comply with the following:
<br />a. Accounts. Trane will ensure that Trane’s personnel use only the Extranet account(s) designated by Customer and will
<br />require Trane personnel to keep their access credentials confidential.
<br />b. Systems. Trane will access the Extranet only through computing or processing systems or applications running
<br />operating systems managed by Trane that include: (i) system network firewalls; (ii) centralized patch management; (iii)
<br />operating system appropriate anti-malware software; and (iv) for portable devices, full disk encryption.
<br />c. Restrictions. Unless otherwise approved by Customer in writing, Trane will not download, mirror or permanently store
<br />any HVAC Machine Data from any Extranet on any medium, including any machines, devices or servers.
<br />d. Account Termination. Trane will terminate the account of each of Trane’s personnel in accordance with Trane’s
<br />standard practices after any specific Trane personnel who has been authorized to access any Extranet (1) no longer
<br />needs access to HVAC Machine Data or (2) no longer qualifies as Trane personnel (e.g., the individual leaves Trane’s
<br />employment).
<br />e. Third Party Systems. Trane will provide Customer prior notice before it uses any third party system that stores or may
<br />otherwise have access to HVAC Machine Data, unless (1) the data is encrypted and (2) the third party system will not
<br />have access to the decryption key or unencrypted “plain text” versions of the HVAC Machine Data.
<br />
<br />3. Customer Data; Confidentiality. Trane shall keep confidential, and shall not access or use any Customer Data and information
<br />that is marked confidential or by its nature is considered confidential (“Customer Confidential Information”) other than for the
<br />Docusign Envelope ID: A027BEC4-9CD8-4C1F-889C-FED6DE495C39
|