Loading...
HomeMy Public PortalAbout149-2021 - IT - CrowdStrike - Master Agreement for Security Services and Products CROWDSTR KE TERMS AND CONDITIONS These-.CrowdStrike Terrns and .Conditions by ar rd between CrowdStrike, Inc., a Delaware corporation, and:any Affiliates,performing hereunder(collective.iy,'!CrowdStrike")with a principal place of.b,asines .at 130 MM€atni€daPla€e,. Suite i lU SUnnyv.ale, Califon-tie 94086 and the party flamed below'in the signature area f"Cu tomor") area entered into as.of the date signed bythe:last party.(this"Effective Date"). These CrowdStnke Terms and Conr:l€tions are a master aier+'ement.that:cover aaril CrowdStrike products and sc.irvicee but provisions regarding specific::products or service ;apply only to the ext ant:Customer has purchased,hased, accessed'or- used such,products.or services. 1. Definitions. "Affiliate'.means any entity that a party.directly or indirectly controls (e.g., subsidiary) or is controlled by (e.g,, parent), or with which it is under cognition rbntrol(e.g., sibling). "Agreement" means these CrowdStrike Terms and Conditions together with each Order. "API"means an application program (or prograrriniirig) interface: "CrowdStrike Competitor" means a person iDr entity in the „business of developing, distributing, or commercializing Internet-Security products: or services aubstahtially :.;iin'ar to or competitive With CrowdCtrike's products or•services.. "Cr'o tdStrike Data„" shall mean the data generated by the CrowdStrike Offerings, including but not limited to, correlative i-ndfor•conte xtual.data, andier de tections. For the avoidance-Of doubt, CrowdStrike.Data does not,inrlude Customer beta. "Crowdstrika.,Tooi"means eery CrowdStrike proprietary software-as-a-service software, hardware, or other.teol that CrowdStrike uses in .peifurrning 'Professional Services, which may be specifiitid in the .applicable SOW. CrowdStrike Tools may inc€uele..Crowd.atrike's p roducts. "Caiaton er" means as the context requires, in addition to the entity ideritifed above, any Cie tdmerAffiliate that. places; an Order under these C:rowd.Strii€L Terms and Conditions, Uses or aa:cesse_. any Offering hereunder, or benefits from the Customer's use of an.Offering, "Casttomer.Contraatctor"„means any'individual Or entity(other than a CrowdStrike Coe:-petitor)t at: (i)has access or use of a Product under this Agreemeint solely on.oehalf of grid for Custorrier a:lnternal cis e (ii) has an.agreement to pr'.ovide Customer(or its Affiliates)serviCie'i,,reed(idyls-subject tt..C:.orrfidentiblity obligations coveriny'Cr6wd.§:triI e`s: Confidential I of+_rr rriation. "(ouStorner Contractor erv:ice i" mearis,products, services'or content developed or proVided by Customer Contractors,.including but not lirnited:to,third party applications complimentary.to the Offerings, implementation services, Managed sor ices, training,technical support or other consulting services related to, or in ccnjun+::tir:in with, the Offerings. "Documentation' means CrowdStrike's end-user technical documentation included in the applicable Offering. "Ei di is>Irii"means any physical or virtual device,such a s .a computer;server; laptop, desktop computer, mobile, cellular,:container orvirtual machine image. • "Error" means a reproducible failure of a Product to perform in.substantial conformity With its applicable Docutrieritation. "Internal Use" means access or use solely for Customer's arid subject to the-Section ction entitled Affiliate ,prder'S and Pavme<ntL-Affillafr s and the Section entitled Access Use Raahts; its,..Affilirtes', own internal information security purposes. By way of example arid.not limitation, lntern<:l iise..does not_indlude access of use: (i) for the CwdFoamtrike.Foam May 2"i.2019 1 rn of 17 Contract No.. 14;9-2021. benefit of-any person or entity'other than Customer or its Affiliates, or (it) in any event, for the development of any product or Service. Internal' Use is lirriited'to access and use. by Customer's and its Affiliates' employees and Customer Contractors (except a set forth in the S 'ction•entitled Castor-net.ContractoN, in either event, solely on Customers behalf and for Customer's benefit. - "Offeringgs''means,i:cllectively,any Products, Product-Related Services; or Profe' sional Services. "Ort er''Meant any purchase order or other ordering document(including any SOW);accebted by CrowvdStrike.or a reseller that identifies the following ordered by•Customer:.'Offering, Offering quantity based.on .CrowdStitke" applica' Ie.license.metrics (e.g., nurnbcr of Endpoints, size of cornr,any-:(passed on hunter of e.nployees), number of file uploads, or number of qi eves),•price. and Subscription/Order Tenn. "Product"means any of'CrowdStrike's,cloud=bas ed software-or•other products ordered by Customer as set.forth in the relevant Order,the available accompanying A-I'S,the CrowvdStrike Data,K;i y.Docurrrentat€on and any Updates thereto that mamaybe made•aVa€lable.to•Oustohier•from time to lime by Cr:+iv,rdSttike, "Product-Related .Services" 'means; co€P t vc ly, (i) Falcon GverWatch, (ii) Falcon Complete Te 3r n, (iii)the technical support services certain Products-provided by CrowdSti ike, (iv)trainig, and(v)any.othier•CrcWdStrike; serviccas.•provided or sold with Products. Prodilct•Related Services do not include Professional Services. "Profes;elonal Services" means any professional services performed'by CroVvidStrikefor Q,ustdrrier purstfeif to, an SOW or other Order. Professional-Services may include without limit:lion iriciderit response, inveStigation and forensic service: ,elated t;i cyber-se'-uiity adversaiieS, tabletop exercises, and next generation genet=itirrn 'test& related to:cyber-security. "Services" means, collectively,and;Product-Rel;ateJ Services and any Professional Services. "StatementofWork"or"SOW"3r3earis a.r3iutuallly-a> rend executed written der:ument describing,the•Professional Services to be performed by CrowdStrike.for Customer, deliverables;fees; and.expenses related-thereto.. "Subscription/Order Trm"Mean the period of tinnc-,set forth in the applicable Ordet during which:(I)Cu tother. is authorized hy.Crowd_Strike to access and use the Product or Product-Related•Service,or(ii) ProfessiOna:l Seniides- array be performed. 'Updates"'means any.corre,+::titian, update; upgrade, patch,es-other modification Or addition-mace.by CrowdStr'ike to any Product and provided to Customer by.CrowdStrike•from time to tirrie on an as available basis. 2. Affiliates,Orders and Payment. 2.1 Affiliates Any Alei€iate•.pu;chasingtrereunder,or using.or accessing any O.ffering hereunder,or bonefittirtg'from the Cu;:tomer's.use of an Offering,will,be bound by and-comply with all tern-is and.conditions this Agreement.: The Customer signing theseCrnwdStr,ke T rrns and Conditions will remain respon Bible for Customer's Affiliates!acts:and omission&un€ess Customer'::s Affilia1:e has entered into its'own Terms and Conditions with;C'rowdStrikee. 2.2 Orders. Only those transaction-specific terms.stating the-Offerings ordered, quantity, price, pay,nent:terme; • Subscription/Order Term,.-and billing/provisioning contact information (and.for the avoidance of doubt, . pccifiically excluding any pre.-printed terms,on a. Customer or reseiler purchase order) ,will have, any force or,effect unless,i particular Order is executed by an'authorized signer of,CrovvdStrike and re.tur;3ed to C uston;er (or the applicable reseiier). If any such Order is so execute and delivered, then only those specific terms on the face of such.Order that-expressly Identify those portions of this Agreement that are to'be superseded will prevail over any•cnnfiictng. terms herein but only With respoct to those Offerings ordered on such orc er. Orders.are_non-cancellable: Any Order through a reseller is subject to, and Cro wdStrike`s ooli rations and liabilities to Customer er are :g1overrled by, this Agreement, • 2.3 Pesmentand Taxes. Customer will_pay the'fees•:for:.Offerirgs to a reseller.or.CrawdStrike':as-set'•forth in the applicable,Order• Unless otherwise expressly set faith=nr thte,Order, CU<at+:Mer will pay t,u fees ani:I;amounts stated on each Order within 30 days after receipt of th'applicable invoice. Except as otherwise expressly pr'ovided.in this Agreement, all fees and Other_amounts are non-refundable. Fees are exclusive..of any applicable sales. use, value CrowrdStrike r`.tiirm May2.7 2619 2 of 17 added, withholding,.and other taxes, however designated. Customer shall pay all such.taxes levied or imposed by reason, of; Customer's purchase of the Offerings rind the transactions .hereunder, except for taxes Based on CrowdStrike's ike's income or with respect to:CrowdStrika's employment of its employees. 3. Access& Use Rights. 3.1 Evaluation. If CrowdStrike approves Customer's evaluation use of a CrowdStrike product ("Evaluaatiion Product"), the.terms herein applicable to Products also,apply to evaivation access and use of:such Evaaluatio;i Product, ext,apt for tl'e following.d€ffr�rarit:or,additional terms: (i) the duration of ti"ie Evaluation is es mutually agreed •upon by.-customer and CrowdStrike, provided, that either CrowdStrikc or Customer can terrnirate the•ev:.iluatiori at any,time upon written(including email)notice to the other party; (ii)'tl;e Evaliiation'Product is provided"AS-IS-without warranty, of any. hind, and CrowdStrike di ciairns all warranties; support obligations, :and ;other liabilities and obligations fur the Evaluation Product; and (iii)•.Custorner's access and use is Iirriited to Internal Use by Customer employees only, 3.2 Access &Use Rights. Subject'to the terms and conditions of this Agreement(including CrowdStrike's receipt of applicable.fees), CrowJStrikc grants Customer, under C::rowdStrike's intei€e:ctual property rights in and-to the applicable Product, a non-exclusive, non transfer ale (except 'as expressly .provided in the Section entitled �lssit rrtrrsnr}, non-sublicensable license to access•-and use the Products in accordance with any applicable Documentation solely for Customer':Internal Use during the;applicable Subscription/Order Term. C;u torner°s access and use is limited to,the quantity in the applicable Order. Eurtherrnore,.the following additional terms and conditions apply.to specific Products(or components thereof): (a) Products with Sofbvare Corn ionents. If Customer purchases a subscription to. a Product' with. a dovwnloadable object-code component (".°oftwar Component"), Ci.istz;rr,er may, during the Subscription/Order Terrn install and run multiple copies af'the Software Components solely for Customer's and'Customer's.Affiliates' Internal Use upto.the,maximum quantity in the.applicable Order. (b) CrowdStrike Tools. if CrowdStrike provides CrowdStrike Tools to 'Customer pursuant to perfort'iiir g Professional nentices, the license set forth iri the Section entitled Access Use.Righfs;applies to such•CrovwdStrike 'Tool;.,as used,solely for-Customer's Internal Use during.the ,e ceded of time set.forth in the applicable Order, or if nor e: it specified, for ti-a period authorized by CrowdStrike. Not ail Professional Services engagements will involve the use of crowdStrike Tools. - is set forth t Section entitled 1^ Rights :�.;i l^�estrrctirn:~". The access and us�..rrgh,� ,rs:t17 in the,Jr i,tifiri Access & Use do not include any rights to,and C'ust n-er will not, With respect to any Offering (or any portion thereof): (i)employ or authrsrize a CrowdStrike Competitor to use or view.thr.'Oftt ring t,r Documentation, or to provide management,hosting,or support for an Offering; (i'i) alter; pulri€icly•display, translate, create derivative works of or otherwise ;modify an Offering; (iii)sublicense., distribute or otherwise transfer an Offering to any third party (axcopt es•expressly provided,iri,the Section entitled .Apsigr'-non') (iv) ailuw third Parties,to-access or u.ie.an Offering.(except for-Customer Con`:radtors as expressly permitted herein): (v) create puiiiic Internet "links" town Offering or "frame" or "mirror" any Offering content on any other server or wireless or Internet-based device; (vi) reverse engineer, decompile, disassemble or otheiwise attempt•to derive the source cede (if any), for an Offering (except to the extent that sut;h prohibitioin is expressly precluded by 3pplir;ahh-'lave),circumvent ant its fi.inetions,or attempt to gain unauthorized access to an Offering or its related systems or networks; (vii) use an Offering tri circumvent the security of another party's networklinforrmation, develop rhalwnre,.unauthorized•surreptitious surveillance; data modifidation, data ea.filtra:ition data ransom or data destruction; (viii)'remove or alter any notice Of proprietary right appearing on an Offering; (ix)conduct any stress tests, competitive br_nctimair'king or aanalysis, on, or-publish any perforrnance data of, an Offering(provided,that this does not prevent Custo:meirfrom comparing the Products to other prradui,ts'f::ir Customer's internal-Use); (r), use any feature of CCr- idStril<e A.Pls for any purpose other than in The aerfor'rhaance of, and in accordance with, this: Agreement; or (xi) cause, encourage or assist,any third party to .do any of the 'foregoing. Customer agrees to i.lse°:an Offering in accordance with laws. rules and reguler•_ions directly applicable to Custotner •and acknowiedaes that Customer is solely responsible for determining whether a particular use of an Offering is compliant with such €a:vs. 3.4 Installation and User Accounts. CrowdStrike. ia- riot resparisible for iriSta fling Products unless Customer Purchases installation services from; CrowdStr'ike. For those Products requiring User accounts, only the single individual•user assigned tit)a.user account may access or use the Product. Customer is liabie;grid`responsible for all CrowdStrike Forrn'May'27 201131 of:17 actions aridomission ;occurring,under Customer's and Customer.Contractor's user'accounts for Offerings. Customer =shall -notify CrowdStrike if Custan'ier learns of any unauthorized access or use of Customers user a scounts 'or passwords-id!.an Offeirifg. • 3.5 MalWare Sarnoles. if CrowdStrike makes malware samples available. to Customer in connection with an evaluation Or use of-the Product ("Maiware Samples"), Customer ai;krioWledges and agrees; that. (i) Custormier's access to and use of Malwcire S;aa;nples is at Custorner''S own risk, and (ii) CLstorner should notdownload Or aCress 'any Mal are Samples on or through-its own production systems and networks and that cloinq so can infect are:_ damage.Custornea's systems,'network. and riata. CuStemer shall use the Malware Samples sole€y for Internal Use and riot-for,any-malicious or uniavfI purpose. Crow=dStrike will not be liable for any lass or damage caused by an;; Malware Sarriple that may infect Custorni_:r's computer equipment, rornputer progrc.ins,, data, or Other proprietary material'dutto Customer's accsss to.Qr use of-the IMlaIware-Samples: 3.6 Third Party Software. CrowdStrike uses certa€n.third party software in its Products, including what is Commonly referred to"as open source;aoftware,. Under some of these third party licenses,.CrowdStr.ike is requircd:to provide Custorrii;r with notice.of the license terms and attribution to the:third party. See the licensing terms anda'ttributians for such third party software.th t CrowdStrike,uses.at.: tittps:llfalcon.cro,vd€str€ke.com/opinloJdmbe. 3.7 Ownership &.Feedback. Products; Product-Related Services and the CrowdStrike Tbols are made available for use.or€icensed, not sold. Crowd .,trikr.owes and retains ail right,title.and interest(Including:all intellectual property rights) in ;and to the.Products, Product-Related,Serncesand the CrowdStrike Deals. Any feedback or suggestions that Customer provides-to CrowdStrike regarding its Offerings and.i.roirydStrike'To.rls (e.g._bug fixes and features requests) is non-confidential and may be used by CrewdStrtke for, any purpose without acknowledgement or cornpensation; provided, Customer will net be identified,l?ubiicly as the scturce.of the feedback or::suggestion. 4. CustoriaEEr'_Contractors. 4.1 Authorization. Customer authorizes CrowdStrike to give Customer Contractors the rights and privileges to the Offerings necessary to enable and provide for Customer's use and receipt of the Customer Contractor Services. If at a:ny time.Customer re,vokes.this atithc.,rizatienetp the extent the Offerings provide ir.ir{:gist"mer to limit the Custurni r Contractor's access and:use of the Offerings,then Customer is re'- onsibie fortaking.tl,a actions i e essary to revoke sucr' access and use. In the evert Customer requires Crowd Str'ike.arsi'tonc=:.with such revocation or limitation. Customer must contact .CrewdStr'ike- Support with written ;'ictic'e of such revocation or limitation at support©crowdstrike.com and CrovvdStrike will disable the Customer Contractor's access to Custorric is Offs r€,sass within a reasonable period of time following receipt of su':h notice but in any event within 72 hors of receipt of.such notice. 4:2 Disclaimer. Customer Coritractors are subject to the terms and conditions in the Agreement while they are using the Offerings on behalf of Customer.and Customer remains responsible for their acts and omis:ions during .such time. Any breech by a Cy.rstonier t,cntaactor of this Agreement is. r breach by C:rsteiric'r. .CrowdStrlk+.i;may make available Custom r Contractor Services to Customer, for e'xarriple, through an online dire~.tory,catalog, store, or marketplace. Customer Contractor Services :are riot required for use. of the Offerings. Offerings may i.ontain feature;, including AP'I's, designed to interface.with,or provide data to Customer'Centractor Services. crowdStri'Ke is-not responsible or liable for,any loss, costs or damages arising out of'Customer Contractor'', actions or inactions in any manner, including but not lira ted to, for.illy disclosure, transfer; Modification OF deletion of Cu::torrier Latta (defined in Exhibit A). Whether or not.a v'usto'-er Contractor is-deisigilatedby.CrowdStrike as, or otherwise.,laims to be "certified," "authorized," or similarly labeled, CrowdStrike does not: (i) control, monitor, maintain or pr•o bide. support for,Customer Contr. for Services, (€i)disclaims;all warranties of any kind,indemnities,obligations,and ether liabilities in connection with the Customer Contractor S orvicrss,and any.Custorn oar contractor interface or-integration with this Offerings, and (iii) Larrnot.rgluarantee the continued availability of Customer Contractor Services and,related • features. If Customer Contractor Services and related features are no longer avell'atwle for any reason, CrowdStrike • is not_,obiigatcd to.provside any.refund,,credit,or other.campenvetion for, or related to, the Offerings. 4.3 Restrictions on Customer C.t ntractors. Custom er'shall not give or allow Customer Contractors access to, or use of, intelligence reports provided by, or made accessible in, the ProdUcts.. For the avoidance of doubt, nothing herein prevents Custi:,m€rr from using intelligence APl's in Customer Contractor Services for.Customer's Internal Use. �. Professional Services. CrowdStriirs Form May 27 2019 4 of 17 - 5:1 • Fees. Professional Services will commence. on. a mutually agreed upon date: Estimates provided for .Prof `s.sioriai Services performed on a tire-and-rn_aterial,basis are estimates only and.not ca.,gr grantee J time of completion. Professional Services performed on fixed fee basis are limited to the scope of services stated in the applicable Order. 5.2 Ownership of Deliverablea. Professional Services do not constitute"works for hire,""works rrtade in the course of duty,"-or similar terms under laws.where the:transfea'of intellectual property occurs on the perforr ante of ser ices to a payor. The only deliverable arising from the.Professid"rral Serviced is a.report oensisting priri'iarily:of CrowdStrike's findings; rec:onimendatioha, and ad ?sar:y information. Customer owns'the copy of the report.(includinifi,,without limit-Alone all of Customer's Confidential information. therein) delivered to Customer ("Deliverable"), subject to C;rowdStrike's ownership of the GrowdSti-ike Materials. Customer agrees-that relative.tO Customer, CrowdStrike exo.usivcly awns any and all software(including object and source code), flow charts, algorithms, docurhentation, adversary information, report tempi tes, know-how, inventions, techniques,.models, CrowdStrike trademarks, idea and any and all other works and materials cievel,•:sped by-CrowcdStri'kt .in Connection with.performing-the Profosvie nal Services(including without limitation all intellectual property rights therein and thereto)(r•ollectiveiy,the"CrowdStrike- Materials")add that title-shall remain with CrovvdStril e. For the avoidance of doubt,the CrowdStrike Materials do not include any Customer Confidential Information or other‘Customer provided m2iteiials or date, Upon payrnertt in full of the amounts due hereunder for the applicable Professional Services and to the extent the Crowd Strike Materials are incorporated into the IDeliverable(s)-, Customer :s.hell have a perpetual, nori-transferable (except as expressly prcvidedJ-in.the.Section entitled-A sighmeht), non-exclusive license to use the CrowdStrike Materials solely.as a part of the Deliverable(s)for Customer's internal Use. 6. -Datta Security and Privacy.. -See.lw-xhibit A.- 7. Confidentiality. Ci+.firition_.. In Connection with this.Agrer:meat,each party('Recipient")-array receive Confidential Information of the other party (Disoloser") or third parties to whom Discloser has-a duty of confidentiaiit';'.. "Confidential Information"means noi'r-public.iriformation.in any form that is.in the.Recipent's possession readies of-the Method of acquisition.that the. Discloser designates as confidential to Recipient or ShoUild be.reasonably known by the Recipient to be Confidential -Information:due tO the nature of'the information disclosedand/or the circumstances surrounding the disclosure; Confidential.Information shall not-include information.that is: (i)in or becornes part of the publir,'dernain(other than.by c is'lo pure;l:y tecii?i+ nt in violation of this A;ireen'ient), tii)previoiisly known to Recipient without an.obligation of confidentiality and dcrrionstraTale by the;recipient: (iii) indepei'ideritly developed by Recipient Without use of Discloser's Confidential information; Ur (iv' riahitfuily obtained by Recipient from third parties without an obligation ofcon identiality. 7.2 Restrictions on Use. Except asallowed in Section 77.E (f:xccptions), Recipient shall hold Discloser's Confidential information in-strict confidence''and shall not:disclose any'such Confidential Information to any third party, other than.to its employees;and contractors:,including without limitation,counsel,.acrounte.nts,and financial ad,uisers (collectively,"Represer'itative?), its.Affiliia,tes-end their Repres,entaiives,subject to the other terms of tilis Agreement, add in each_came who need to know;Such information end who are bound by restrictions regarding disclosure•and use of such information comparable to end no less restrietiva than those set forth,herein:. Recipient shall not use Discloser's.:Confidential Ink rn°iation for.dry purpose other ti-ian:as set forth in this Agra e n'ie nt. Recipient;smite take. the same;'oegr'gc'of care;th:itit Cises:Eoprotect its own confidential Enfor'rnatiori of a.sirn'rlar nature and in-port:ante(but in no event less than reasonable care'to.protect the confidentiality ,and.avoid the unauthorized use,-disclosure, publication, or dissemination of the Discloser': Confidential Information. w^J'ithin 72 hours of Reripient_becoming aware of the unauthorized'use, disclosure, puk li+:ration, Ur'dissemination of the Discloser's Confidential Iriforrrio_tioil. while in Recipients control,.-Recipient snail provide Discloser with notice,thereof. 7.3 Exceptions. Recipient may.disclose DISC lo:,.er's C pr:fid.enti.ai Infori -iii)r'i:(i)to the extent required,by applis:,abie law or regulation; (ii) pursuant to a subpoena or order of a court or regulatory, self-regulatory., or i+egislative.body of competent jurisdiction; (iii)in connection with arty regulatory report, audit, or inquiry; or (iv)where requested by a regulator with jurisdiction over Recipient In•the event of.suchi a requirement or request,.Recipient nt shall, to the extent legally permitted; (a) give Discloser prompt written notice of such requirement or request prior to such disclosure; and (b) .:it Discloser's cost, a reasonable opportunity to review and cornrtrerit upon the disalosure and -request confidential treatment or.a protective order pertaining thereto prier to Recipient making such disclosure. If the CrowdStrike Form May 27 2019 .?of 17 Recipient is legally required to disclose:the Disclbser's Confidential Information as part of: (4-..a legal-proceeding to. Which the DiSC to ser is a party but the-Recipient is neit;,or(y)a government,or reguiatory..iriveetigatiori of.the Discilcisi t 'the Discloser shall pay all of the.tech ient's reasonable and actual cut of pocket legal fees.aid expenses.(as evidenced.by reasonably detailed invoices) and will reitriburse the Recipient for its reasonable costs aired feee of cornpiling and providing.such Confidential €nfoimation, including, a reasOnable iid i.irly rate for time spent preparing for, and participating in,depositions and othertestirrony: 7.4 Qestrgpttion, Upen Discloser's written.request, Recipient Shalt use ccr7imercir;-illy reasonable efforts to destroy the Confidential Information and any .copies_ or extracts thereof. However, Recipient, its Affiliates and their Representatives may regain any Confidential Information that, (i).they:are requiredto keep f"r compliance purposes wider a.rrbcurr..rt retention policy or as required by'applicable law, professional Standards,a could;.or regulatory agency;or(ii)have been created electronically pursuant'to automatic orordinary course archiving, back-up,security, or disaster recovery sy rterris or procedures; provided, however, that-any such retained.Infort atiori shall remain subject to this Agreement..Upen Disclosers request, Recipient will provide Discloser With Written confirmation of destruction-in compliance with this provision.. 7.5 EcuitablE;.Relief. Each party acknowlei lges that a.breach of this, Section'i- (: onf.+ri ntialirr) shall ca..se the. other parry irreparable injury and.oamage.Therefore,.each party Cgrees thatthose breaches may hie.atopped-through injunctive proceedings-in-addition to any other rir'hts and remedies which maybe availabl to the injured party-at law or in equity Witheut the posting-.of:a bond. .8e Warranties&l i.sci aliriar. 8.1 No Warranty for Pre-Production Versions. Any pre-production feature or version of an Offering provided to Customer is ezperimentaf'and provided-'AS iS' with bill-warrantyof'any kind and_willnot create.'any obligation for CrowdStrike to Oontir;uc.to develop, prodi ictize,.support;repair,offer'1'or gale,or in any other-way cr i tiriue to provide. Cr develop any such feature or Offeringg. .Customer agrees that:its purchase is not contingent on-.the delivers.of.any fiitur: furictionality or features Or-dependent on any'oral or Written statements made by CroWdStrika regarding future functionality or features. 8.'2 Pritiduct Warranty. If Customer has purchased a Product, CrowdStrike warrants to Customer during the. applicable. SUoscription,Order Team that:.(i).the Product will operate without Error:and (ii) CrowdStrike has, used industry standard techniques to prevent:th€ Products,at the time of delivery—from—injecting maliclons software viruses into Customer's endpoints Wherethe rrooucts,are installed. Customer i er must notify CrovedStr ke_of any.warranty claiirn during the;Suoscription Order_€'errn. { ustomd is sole and exclusive,remedy and,the;enti e li big fy of CrowcdStrike for its breach,of this warranty will-be for CrowdStrike, at-its own expense to cc'at.least ono: of the,following: (a):use commercially reasonable efforts to provide a wok-around or correct such.Error; or.(b)terminate Custom=er's license, .to access and use tied;applicable non:-conforming-Product and refund the prepaid fee prorated:for the.unused period of the Subsi flptioniC)idei 1.erm. CrowdStrike.shall have no obligatioi regarding Errors reported after the applicable Subscription/Order Term, 8.3 Services Warranty.. CrowdStrike warrants to.Customer that it will perform all Services in.c professional and workmanlike;ii:gran:r•consistent write gpneraally accepted industry standards, Customer niust.notify CrowdStrike of any werrarnty.claim for Services during the period the Services are being performed: or.within,3Ci;clays after tee c.inciusion ofthe Services, ctisforperp sole arid exclusi,ve:remedy and.tr o entire liability o,C ovvdStrike for its broach of-this warranty'will be for CrowdStrike, at its option and expense,.fo (a) use commercially reasonable efforts to re- perform the non-conforming Services, or (b) refund the•portion of the lees paid attributable-to the non-conforming Services, €3.4 Exclusions. The express warranties do-not apply if the applicable Product:or Service: (i) has been modified; except,by.CrowdStrrke, (ii) has not been ((stalled; used, or maintained in actor dance With this:-Agreement or Docurneritatiori, iir (iii)a:; no.n-i'wfoi'mi3'ig due to a.failure,to use an applicable Update.. if any:pert of-a Product or Service references websites, hyoertoxt links, network-addi•.sSes, Or other third party locations, information,.or activities, it is provided-as s a convenience only.. 8.5 No Guarantee. CUSTOMER ACKNOWLEDGES, UNDERSTANDS; AND AGREES THAT CROWDSTRIKE DOES NOT GUARA.NTEE.OR WARRANT THAT IT WILL FIND, LOCATE, OR DISCOVER ALL OF CUSTOMER'S CrowdStiike Form rally 27 2019 6 or 17 OR ITS-AFFILIATES SYSTEM THREATS, VULNERAI3ILUTIES, MALWARE, AND MALICIOUS SOF1WARE, AND CUSTOMER AND I°€S:AFFILJATiES WILL, NOT f•Ic LD CRO'iNDSTTRIKE RESPONSIBLE THEREFOR. 8.6 Disclaimer. EXCEPT FOR THE EXPRESS WARRANTIES IN THIS SECTION 8, CROWcSTRiKE AND ITS AFFILIATES DISCLAIM ALL OTHER WARRANTIES; 'WHETHER EXPRESS; IMPLIED, STATUTORY OR OTHERWISE. TO THE :MA 'IMUM EX17ENT PERMITTED UNDER APPLICAS E LF:W CROWDSTT-th<E AND ITS- AFFILIATES AND SUPPLIERS SPE.CIFICALL:t'DISCLAIM ALL IMPLIED WARRANTIES or"l'MI .RCHAN TAil RY, FITNESS FOR A P;;R;I-ICULAR. PURPOSE, TITLE AND NON-INFR!NGMEN1` WITH RESPECT TO THE OFFERINGS AN)) CROWDST R)KE TOOLS THERE IS NO WARRANTY THAT THE OFFERINGS OR CROWDSTRIKE'robi4 WILL BE ERROR FREE OR THAT THEY WILL OF'ERAT'E WITHOUT INTERRUPTION OR WILL .FULFILL ANY OF CUSTOMER'S PA.RTICUI.AR. PURPOSES. OR NEEDS. THE-OFFERINGS.AND CROWD STRIKE T'OOLS,ARE NOT'17 AULT-TOLERAANT AND ARE NOT-DESIGNED OR INTENDED:FOR USE IN ANY HAZARDOUS ENVIRONMENT REQUIRING FAIL-SAFE_PERFORMANCE OR,OPERATION. NEITHER THE OFFERINGS NOR'(7 ROWDSTRIKF TOLLS ARE FOR.USE IN THE OPERATION.'OFAIRCRAFT:NA`{iIG,ATION, NUCLEAR FACILITIES, COMMUJNICATION ,SYSTEMS,f EMS, WEAPONS' SYSTEMS, DIRECT OR INDIREQT LIEF SUPPORT SYSTEMS, AIR.TRAFFIC CONTROL,i'ROL, OR AN1°APPLICATION OR Ii'J,?;FALLATION WhEf E FAILURE COULD RESULT IN-DEATH.,"1 H, SEVERE PHYSICAL -OR-PROPERTY DAMAGE. Crjatorner agrees that`it is Customer'.. res'porisibility to e'isurp safe. use.of an Offering and the Crow.wd Strike Tools In Such aopl cdtiona; and installations. CROWOSTRIKE DOES,NOT WARRANT:ANY THIRD.PARTY PRODUCTS OR SERVICES.. 8.7 -Additional Terms That-Itl May Akpoly. See:Exhibit C fr r edditioi:iai tivarranties that rnaiyapply to..certain Customers. ..9. €idemnification, 9.1 CrowdStrik 's.C}bli+( ititrr Crr wd trike shall at its,°cost and expense: (i)defend and/or settle arty claimbrought against CuStornei- by an unaffiliated third party alleging that an Offering infrinrges or violates tray third :pates intellectual prop:rty r ights,.enc (if)pay end indemnify any:sr.ttlernefit of-such claim er'an;j+daniagaS awaroed::to snrh third party by a court of cori:petent jurisdiction as as result of si-irli ClCiir;i; provided that Customer '('ca)gives C;rowd3trilce prorript-Written notice of such claim; (b) permits Crowd8tril,ze to soieiy ccntrol and r direct t e defense.or settleMent Of si.::h claim (huw*ver, t row_dbtril e will not:iettlr.any claim%in as ma:lnrier that requires t I i.torner to admit liability without Customers prior written conse:�t3, and (c) provides CrooWdStrike all i'e sorE�ible aSsIStano . in connection with the deffense_or seettlement of such claim,at CrowdStri}e's coat.and expente: In addition, {..ustorner may, et Customer's own expense, participate in dcfense.of any claim. 9.2 Rernedies If ra claim covered under this section occurs or in CrowdStrtke opinlein is reasonably likely to occur; CrowdStrike_may at its expense arkd sole discretion (and if Customer's access and•r,se of en offering is. enjoined, CrowdStrike will, at its expenbe): (i)procure tr:ie right:to allow Customer to continue aping the appliciole Offering; (ii)modify or re'pia-ce. the aapp.licable Offering to become non-infringing: or (iii) if neither (i) not (ii), is commercially practicable, terminate Custonia s license or access to the-affected,portion of applicable Offeeirrg.end refund a portion of the pre-paid, 'uMiused fees paid: by Ci;;storner corresponding to the: urnsed period of the Subscription/Order Terris. 4 i Exclusions.. CrowdStrike shall have no obiiga.tiorls.under this Sectir. n if the.claim-is.bated upon or arises:ortt of (i)any modification to the applicable Offering not Made by CrcmiStrike; (ii)any'.Combination or use of the eapplicaktle Offering with cr'in any ti:iEid Party software, h.:arc'lware; process, firmware, or data, to the r e:<tei-it'thaat'such claim is based on Such combination ;r'use, (iiaJ C,ustomer's continued use-pt the'allegedly infringing Offeriri after being notified of the Infringenient Claim or being provided a modified version of the Offering by Crc.,wdStrike pit no additional cost that is intended to.address such:alieged infringement'(w).Custumi:r'sfailure to use:the Offering in accordance with thy;.applicable:Documenti:ifiori; sand/or:(v) Custoini-;i s use of the Offering outside the scop"e::of:the r fights granted Under this Agreement. 9A- Exclusive Remedy. THE REMEDIES SPECIFIED IN THIS SECTION CONSTITUTE.CUSTOMERS SOLE AND EXCI..USI`JE REMEDIES, AND CROWDSTRIKL.`S .ENTIRE LIABILITY, WITH RESPECT TO .ANY INFRINGEMENT OF THIRD PARTY INTELLECTUAL PROPERTY RIGHTS. td. Limitation of-Liability, CrowdSti ke Form May 2T2019 7cf 17 10.1 TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EXCEPT FOR LIABILITY FOR ANY AMOUNTS PAID OR PAYABLE TO THIRD P,ARTIES.UNDER SECTION 0 ONDEMNIFICAT-IONIcusromERs PAYMENT OBLIGATIONS AND/OR ANY INFRINGEMENT.OR MISAPPROPRIATION'BY ONE PARTY OP::rHE 'OTHER:PARTY . INTELLECTUAL PROPERTY RIGHTS,. NEITHER PARTY SHALL BF LIABLE TO THE. OTHER PARTY IN CONNECTION WITH THIS AGREEMENT OR THE SUBJECT MATTER -HEREOF (UNDER ANY THEORY OF LIABILITy WHEIHLR IN CONTRACT, SFATI3r ToRT. OR OTHERWISE) FOR ANY LOST PROFITS, REVENUE., OR SAVINGS, LOST BUSINESS OPPORTUNITIES, LOST DATA, OR SPECIAL, INCIDENTAL; CONSEQUENTIALi CDR-PUNITIVE DAMAGES, EVEN IF.SUCH PARTY HAS BEEN..ADVISED OF THE Po,s0i0i.:itY'o sLi.(3171 DAMAGES OR LOSSES OR SUCH DAMAGES OR.LOSSESWERE.REASONABLY FORESEEABLE; OR, (•E.4•) •AN AMOUNT THAT 'EXCEEDS THE TOTAL FEES PAID OR PAYABLE TO CROWDSTRIKE F()RTHE-RELEVAN-1 OFFERING DURING TilAT 0 FEERI NC,"S'SUBSCRIPTION/n.RDER TERM. THESE LIMITATIONS WILL APPLY ,NOTWITHSTANDiNG.ANY'FAILURE'OF ESSENTIAL.PURPOSE Or ANY REMEDY .SPECIFIED IN THIS AGREEMENT MULTIPLE CLAIMS SHALL NOT EXPAND 'THE LIMITATIONS SPECIFIED.IN THIssEcTION1r. 10.2 Addifional.or Different TermsI4t:Mei_Applv, See Exhibi(C for additional-or different terms related.to liability 'that may apply to certain Ciistoriiers.. 11. compliience.with-Laws.•Each party agrees to comply With all U.S,federal,state, local and,nen-U.S.laws directly applicable to such party in the perfOrMence.of-_•this Agreerne,rit, inducting but nut limited to, applicable-export anel import enti-corruption.,4Eind-etplOyment laws Customer..acknoWledgeS.prid agrees:lhe Offerings shall not be used, trapsfeged,, or citherwise.-.6.kPOrted or re7eporied.to regions...that the linited States and/or the European Union maintains an ernh.argo or coMpfeherisivesanctions (Collectivaly,'"Ernbargeed Countries"), or to or by a national or reeident.thereof, cr.any person Or entity subject to individual'prahibitionsfeg. parties listed Oh the US: DepartMent of Treasurys List'of Specially Designated'Natonals or the U.S. Department ofCornmerce's Table of Denial Orders) (collectiVeiy,"Designated:Natierials") Withqut first obtaining all reOuired auttiorLzations from the U.S.gOlernmerttand any other applicable,goverrinient Custr.iMer represents-and warrants that Customer is no boated in,.or is under the control of, drz.national or resident of,an Embargoed.COuntry or DeiSii:mated National. CrowdStrike repreSentSand arrants that CrowdStrike is ntit icicated'in, or is under the control & ore national or resident of, en Erilbal:geed Country or,Desionated National. 12 US. Government End Users. 12.1 Commercial Items, The following applies to all-acquisitions- by or for the'U.S.: government or by any U.S Government prirne contrabtor or sbbcontractoretany tier("Goyertin-lent.UserS").under any Li:S.-Government-contract, grant, other transaction,.or Other funding agreement. 'hie products, CrowdStrike 'Tools, and Documentation are •commercial items,."as that term is defined in Fedora/Acquisition Regulation (TAR'')..(48 C.E.R.)2.101, consisting"commercial computer software!and"commercipicomputer software documentation,"as such terms are.used•in FAR 1)21 1 and Department of Defertse-FAP-c3upplernent("DRARS1•252.227•4015 (Techni(al Data Commercial Itarns) plies to data acquired by De:Tan:merit of.DefenSeageocies, Consistent With FAR /2.211 end 1.2212 and DFARS.,(48.O.P,.11)--2271202-1..throctgh 227.7202-4, th .Produdts CrowdStrike loots ad DocUrnentation:ere being licensed te GoVerntnerit USerspursuaritto the.terrnSrif This license(s)customarily provided to the public as:forth'in this Agreement, unless:-Syqh terms ere inconsistent.with United States federal law("Federal Lave). • 12.2 Disputes with tne...!.L.5.. Gpv.ernnient. If this Agreement fails.temeet the GOVernrnent's needs,or is inconsistent in any way.with Federal..La.W and the,parties cannot reach a mutual agreernent.on terMS'for. this Agreement, the Government agrees to terminate its use of the Offerings, In the event of any.ditputes With the U.S. Government in connection with thi,s,1.kgreernent,Section 14.3 of thiSAgreement,shall not apply„ Instead the r grits,anci duties of the Parties arising front this AgreeMent :Shall be governed by, construed, and enforced in accordance with Federal ProcureMent Law and any such•dispUteS-.shall be resolved pursuant to the Contract Disputi.s-s'Act. of IE)78, as' amended,'(41.U.S.C..7101-7109), as'implemented bY the.Disputes Clause, FAR 52.233-1. 1.2.3 Precedence. This US:Government rights in,this Section are in lieu.of,andsupertedes,.any other FAR;.DFARS, or other.Clause,_provision, Or supplemental regulation that addresset. dovernment.rights.in the blering., computer software or technical data-under this Agreement: • CrpvidStrik6 Fc.idn may 272019 8:of 17 13. Suspension-and Termination. This Agreement shall remain effective until termination in accordance With this Section or as otherwise spi crf ed herein,. C;roved Strike May immediately suspend.Customer's across to, or use s f; the Offerings,it (i) CrowdStrike believes'that'there is,a significant threat to the: se.curity, integrity, functionality,.or availability of th e.Offeiings or any content; data, or e oplications in the.Offerings; (H)Customer or Customer users-arc: In breach of:SEec:tion 314 ( 'osirk:ton.); or:(iii) C u tUri e fails to pay .Crrvvd trike:-,when Line isputed fe3es are provided, 'howeve:r, C;rowdStrmke. will use rornrmercially reascnablr. -efforts under the dirG.umstances•to iiroVide Custon er with notice.and, it applicable; an opportunity to remedy such violation prior to:any such Suspension. Either party rney terrnin. to.this Agreement upon 30 drays' written notice of a material.breach by the-other party;:uniessthe breath IS riured within the 330 da.y notice period. i'rior to termination and subject to'the term. of this Agro ment, Customer shall have the right to access sand downioi d:Customer lntati _rvailable per the Customers pur.ihased Products and dite retention period in a manner;and mr,a iformtiat supported by the=Pr{:iducts. .I con ter€rination of this Agreement for any reason:- (a) ;all Customer's amci s ; end use'rights granted in this Agreement nt will terminate; (h)Customer must promptly cease all use of Offerings -aanc; de-instal all 'Software Components installed or€ Cus'torner,sEndpoints,and.(+a)Customer Data Wii€tap deleted in accordance with thedata retention period purchased by Customer and'Section 4 Confident+ litE Desrructlorr)<-Scctions 1., 3 4,7, 10, 12, la,-and 14 and all.liabilities that accrue prior toIerrnination'shaii.survive ekpiratiOn or termination of this.Agreement for army reason.. 14. General, '14.1 Entire Agreement. This.Agreement constitutes the entire.agreement between, Customer and-CrowdStrike concerning:the subjec;t:MatterCF'this Agrm emerit and it soup ri,edcs all:prior and Sirnultaneou,s prol,mosals,-agreemen:t,, undorstandings, or other corrimuniratiori between the f.arties, oral or •written, regarding such subbed matter. Notwithstanding the foregoing; if you have a CrowdStrik=e LiO771rp :el!`arr•arifv Aoreernt rr(y Edicon:Comp;etd (or a preceding or sUc,cesso€ imamned product)fully ekeouted with CrciwdStrmke,the.ar;-arianty pr hided:th rein stands and is notsupe:rscded by'this Aoreemorit. It is expreSsly. agreed that:thm,. t mrrim of°his,A:greernent shall supersede any terms in any procuremeritinterriet portal.or other similar non-Cribwd.Stnke document:and no suich tern s inciuded in any such portal or other non-CrawdStrike dOcurniant F.ihEzil apply to the C`1ffarnrjs ordered. Any Order through,a reseller is.subject to,and .0 mowm lStril.e s obligations and liabilities'to Customer are governed by, this Agreeme rit:. CrowdStrlice is:not obligated under any reselier's ac reernent with you ifnles. .an:officer of CruwdSfrike.executes the; agreement: 'This Agreement shall not be curstrued for or aagairu t any party to this Agreement because throat:party or that party!s legal'repre;°.tentative drafted any.of its provisions: 14.2 Assignment. 'Neither party may:assign this Agreement without the prior written consent of the other party, except to-en Affiliate in.connection-with a.cerporate reor.0anif ation or in:connection with.a merger, accluisitiorl,, or sale of all or substantially all of its business nd/ r'assets. Any assignment in violation of this,Se:ction shall 'be void. Subject to the foregoing,;all rights and.obligaticn>>of the parties uncles'this A groom.tent shall be binding ig upon and inure to the benefit of;end 1:K4:enforceableby and against the successors nd.permitted assigns, 14.3 Governinq.Law:Venue.Except asotherwise provided in Exhibit B(if applicable),this:Agreement, and the rights: and duties of the parties arising from this Agreement, shall be governed by, construed, and erifoiced in eccordence with'tne laws of the tate',of California, excluding its coruflicts-of-law prin ci Jle.. The.So'e.and e>elusive jurisdiction and venue-:for•actions.arising_under this Agreement shall be state and federal'oust in Sa ite Clara Cc nty,California, and the parties agree to service of process in accordarice with the rules of'such coure. The U iform Compo,ter Information Transac;tions Act and the.C1nitrd Nations Ccnveitiori onthe International Sale of Ge.5ds shall not apply.. Notr,+ithstranding thcforegoing,each party reserves the'right to filea:.suit-or action mi in any court Of coriipetermtjm.mriadiction as such party deems,necessary:to protect its intellea:'timai property rights.and, in CrowiStrike's case, to recoup any payments due, 14.4 Independent Contractors: No Third-Party Rights, The parties are independent contractors.. This Agreeri-ent. shall riot ettahlish any relationship of partnership, joint venture, enmplsyment, fr'anchiSe; Or agency between, the. parties. No"proVisiorm in this Agreement'IS intended or shall create any rights with-respect to the subject- atterof this Agreement in any third party. 14,5 Waiver. Severability & A mendments. The failure of either party to enforce an.y provision of this Agreement shall riot constitute a waiver of any other provision or any sL.hseguent breacih. If army'provision of this Agreement is held to be illegal, invalid, cii unenforceable; the provision'Will:be enforced to thee:maximuim'extent'perrnisSible_ o.as to affect the'intent of the parties, and'the remaining provisions of this Agreerhent will rerhain in full force and CroWdS.tr ke Fbrm May 27 2019 9 of 17 • :effect. This Agreement;may only.be amended, or any tern or condition set forth herein waived, by written consent of both parties. 14:6 Force Majeure. Neither party-shall be'ilahle for,nor shall either party be Considered in bre.ach::bf this Agreement: due to, any fallure.to perform its obligatizns under this.Agreement(other than.its payment:obliga€ion.:) as a result of a Cans ' beyond its control, including but:not limited to,.act of God or a public enc rny, act-of any military, civil or regulatory authority, change in.any law or i`EigUlatiOel,,tire,floo+d earthquake, sternr;:rr other 1€l e egent, disruption ci _outage of cornrn rn cations (inclucing an upstream-.server block,-and Internet or Other networked enVirornntent disruption or outage); power or otte r-:utility, labor problem, or ony.other cause,vwhether'similar or dissimilar to any`of the_foregoing; which could not have been prevented With reasonable-care: The:party£>,pf-:rieriring 3 force majeure, event, shall•use commercially reasonable efforts to ,rcvide.notice of such to the other party. 14.7 Notices.. All legal r btic s will be given in writing to the-addresses in the first €ntrodE ctciry.paragraph] of this •Agreement and will be effective:(i)when personallydelivered, (ii)On the reported delivery date.if sent:by a.recognized internationai:or overnigtht ccs.irter, or(lii)five basin ,as days aft+ r t eirtg serif oy registered or certified mail(or ten days -for international rnail). For clarity, Order.,, POs, Coffin-nations, invoices; and .other documents.relating to Order processing and payment are not-le.gal notices end may be delivered electronically:in accordance with each party's standard Ordering procedures. 14.8' €]natures. .This Agreernent.'and any Orders:may'be_executed In two Counterparts, each of which will be considered an original out:all of which tOgether;will constiti to one"agrternent. Aaiy signature.delivered by electronic. means,shaill.be:treated focall purl:toseea an:original. € EGAL NAME OF CUSTOMER: By: By:, Name: Name: • Title: Title: Date: Date Send rtoticesto: Notice Address: 150 1'4AI-llda Place, 3rd Floor. Address; Sunnyvale; CA 94086: City: State: Zip: __.._. With"a.copy to:legai .crowdstrike:com Attn: •CrowdS,riko FarmMi y 2-7 20'19 '4 ef'17 Exhilit;A:Data Security'and Privacy Schedule Io Definitions Craawd mer° a CF a�tr�ilte Syvsteivat" means those computer systems'hosting the `Faic,on EPP`Pfatfurn-C. h: Custo Data, inr:.ans the dfi:ita generatco by the Gustonler's>Lridcointand tolledted by: (i)tl e-Predtie ta;, and,or(ii)'.the Crows:trike Tools, .and n either rase, sent to the C;rnwdStriIce Systems: C ustoM r Data is considered Cu'storner's:C oniiriehtii i infcrrnatfuh (definud.in Section I Coniiidei,tiahitaV);arid sub ect to the exclusions; r xceptior is aril otbligatierr st i forth:the rein anti this'Exhibit A Dataj2or urrty and Pr,vaa:v Schedlli& c 'eExerartioii tar6filenViet:rrt. Data".means any machine.-erierate.d data, such as metarfata derivec,f em testis, file ,°,cecutiooai, commands, resources, network teft.metry, executable binary,files, ft-iacr s, scripts,. and prcr esses,"that: {i) Customer provide to CrowdStrike: in connection. with this..Agreenientcr (i) is coilected or disc oVered• the, course of Crowd Strike. providing Offerings, Eycludiriq any such information or data that ide nfiheS Crntorncrr.orto the extent it includes €mrsonalData. d ".Peraa,onat Data" means rrrirormatrorr provided by Custorher to C reWdStrike or.collected, by t roW:dStrikc.: from'Customer used t i distinguisf i or trace a natural person'.identity; either r€ane or when combined with other personal rr.identilyirg infu+rrr ation.that or Iinkabl by CroWdS r€ree-tc a speieific natural person. Personal eta also Includes such ether information about:a specific n.iitur i,perenr to-:the'extent that the data protection laws apLl€cable in the.jurisdiict€ons in.which soar'person resfdes.d-oofinc ouch infcrmatiori rs Personal Data,. e ''Privacy'and d+. Wray i.aw "Mer:!'is U:S, federal, state arid local .and nrori�t1.S, laws; including arose of the.European Union; that regt.ilate,the prrvec:y or security of`Per•sonal'Data and that.are.directiy applicable to C:CrcwdStrike f "Security preach" means urratuthori.ced access to, or un:authorized:.c-ae gititifion of.(i) Customer Data, or (ni Per-onaf Data, stored on CfowtiStrike'Systems that results in the cr r ipromise-of such C rrsterner,Data and/or Data: g FThreat•,Actor Date- mean any telw:are, spyw ire;_ virus, worm, Trojan. horse, or other.peters ally malicious err harmful rodeo or files IJRLs DNb data network telemetry; cornmmarrds processes technitfues metadata, or other iriermation or data, in each case that`ic potenti<alHy.related to unauthorized third parties associated therewith and that (r)c istome provides tau'CrowdStrike in connection with this Agreement or(ii) is co€lei':ted or discovered during the;cour;ie ofCrowd Str rkc,'pre iidri g Offerings,excluding any such information°or'data that'identifies Customer or to the extent tliatit inciudeS.Pc oral pate, Falcon Platform 'l"he`Falcon EPP Platform'use a crowd seourceu eriv.ironment, for the ben-it:fit of i ll ouster—refs, to help customers proter t'i:hem elves agaiostsuspre ions and Or.,tentiaifiy destri.rctrvc activities. CrewdStrikes Products are designed to detect, prevent, respond for and'identify irrtrmsior'is:by collecting'and analyzing,data, ncludii'g machine 'event data, executed sorrpts, code, system files fog floss dff fries, login data, birary file, tasks,'resouroe,information, •comman's protocol identifiers, UR1_s;, nr twark datri, ;irrtdlor othcar executable t.ode and rtietadate rsustc rner, r:rt-icr than CrowdStrike, determines which types 6f data, whether Person-al Data.:-or net exist on its iyst u:s. Acoordii'rgly, Customers endpoint e n irehment IS unique, in torrfgurationsi arid. naming '00riventionS and the machine're event .data could potentially rally include Personal Data, Growdstrike uses the data t:is (1) analyze, Characterize, attribute,'warn n of, and1or respond to thrertS against Customer and Other Custorrie'ir, (ii), analyze 'trends.aoc'performance, (isi) improve'the functirraai ty of, and.dievelop,C r:wd trikee's products and'-ervice s,,and enhance c rherseuurity and (iv) parr nit Castaarriers to leverage other applications theft"use-the data but for all of the foregoing, in a way that does not:.identify Gust:ornerier CusturmiEir"s Personal Data to other custarners. Neither Execution Profile/Metric Data nor T:hreatActor Data are Ctistorrier'sd on idential lrifbr—atierr Or CUistorner Data. 3. P:rtace&ifn ; Perr onall Data ,a Provisioning/Use—:of Offering . Personal Data May be cnlhec ted and asps d during the i,rovisihning aid use oaf the Offerings too deliver, support and lrnprove the Offerings, administer,the:Agreement gr+ ement and further the business relationship between C ustorner and CrowdStr ike, con-1ply with law; .act accordanta .prim Customer's written instr:actiarr:.;,, or otherwise fn accordance with this Agreement. Customer authorizes Crowd.Strike to collect, use,store; and transfer the Persenal Data-that,Customer provides t_r CrowdStrike art contermplated in this:Agreement proyydStrikE l rr ty May27 2Q15 1'i of 17 b. SuspirDious/Unknown File Analysis. While uPing certain :CrowdStrike Offerings Customer may have the.. • option to upload (by subrnis.Sion; configuration, andlor, in the case of Servicep, by CrowdStrike personnel retrieval) Thee and other inforrnation I-elated to the 'files for s-ecurity analysis and response Or; When submitting.crash reports, to rraf<e the product more reliable and/or improve CrowdS.tiike's prat:Note arid services.pr enhance cyber-security. These potentially Suspicious or-unknown files may be.transmitted-and analyzed to determine functionality and -their potential to cause instability or damage to C:3stomer'S endpoints and systems, in some instances,these files could•contain Personal Data.for which CuStorner is responsible. 4. Compliance with Privacy.and InfOrrhation Sedurity ReiVirements Comoliance With Lavvs. CrowdStrike shall comply with all Privacy and-Security Laws, the EU-US Privacy Framework and the Swiss-LIS Privacy'Shield Framework:as set forth by the, US Department of Commerce regarding the collection,Use,and retention of Personal Data-from the•European Economic,..Are,a, SWitzerland, ;and the United Kingdom, as EiOlicable, CrowdStrike's. privacy notice. may be found at httoffiv,rwwcrciweistrike:coth/orivao-noticeL To the extent necestary to comply with-Privacy and Security Laws,including but not lirnited to when Customer is a controller of Personal Giotto processed by Crowdtrike originating in the European Linion, Switzeriani:i or the United Kingdom,the Data Protection Addendum pet forth here https://www.CIOWASttike..CernIdata-protection-z.,,greernent, Khali apply to CrowdStrike's processing of such Customer Personal Data. b. 5.4requards. CrowdStrike sna mutciin appropriate: technical and organizational safpg6erds commensurate with the sensitiVitY of the Customer Data and Personal Date processed by it on Custer:re.'s behalf,which are designed to protect the security, confidentiality,..and.integrity of such:Customer Data aid Personal Data and protect such Customer Data and Personal Data against ,acs:identai or unlawful destructiont loss; alteiration; unauttiorited ciitclosure or:access, including...the safeguardstp forth on Appendix 1 which substantially "conform tO the. ISO/IFC 27CO2 control framework. ("Inforrnation Security Controls:for.CrowdStrike System's"). c. Access: Coritacts.With respest to eMployees, agents, and subcontractors, CrowdStrikc.shall limit access to Customer Data arid Personal 'Data to tiny those ernplOyeeS, agents;-and subcontractors Who have..? need to access the Customer Data and/or Per "rat Data in order to carry out their ntlea as conternplated in the terms,of this Agreement: CrowdStrike-shall assign and train personnel who shall: (i) customers regarding any issue s cenaerning the security of Customer Data and/or Personal Data; (if) 'receive notice of any Security Breach discovered by CrowdStrike and provide notice pf any such Security Brp•ach-to Cue:turner; and (iii) obordinate CroWdStrike's Security Breach.rpeponse and remedial aCtien, 5. Security,Breath Illesnnse In the event CrowdStrike discovers aSeeurity Breach,•CrowdStrike shali: a. Without undue rielay but no later than 72 hours of becoming mvare, notify Customer of the disciDvery Of the Security Breech. SuCh notice shall Suminarize the known circumstances of theSecurity Breach and the corrective actienfteken or be taken by.CrowdStrike. b. Conductan inve..stigation of thecircumstances of the SeCUrity Br.each. c. Use cornmerdally'reasonable efforts to rernediatethe Security Breach. .d.,. Use coittrrithrcially reatbnable efforts to communicate and cooperate, with custtirter concerning its response-to the Se.durity Breach. 6, Security As merit and Provision of Audited Security Controls. Promptly after written (including email) request from Custerner, CrowdStrike shell provide. Customer with (i) its mist recent $0C U Type.2 repot redarding the CrowdStrike Systems::and (ii) provide its complete:I Standardized Inform tion Gathering (SIG) questionnaire (or similar document) or the CrowdStrike. Systems (the 'Security Documentation"). Upon the provision of reasonable notice to CrowdStrike, Once every twelve months during the'tenti of the Agreement and during-normal bUsiness hours uriless..otherwise decided-by CrowdStrike in its solo disCretion, CrowdStrike shall rnakeappropriateCrowdStrik;a,personnel reasonably avallable-to CuStomer to discuss CrowdStrike's manner of .compliance with 'applicable security obligations under .this Agreement. in ,advance, of such clitcussions CnOWdSttike ring, in addition to the Security Documentation, provide Customer with access to tildditiOnal reiqueSted inform non or documentation.concerning-CroysidStril.ze's infprination,seourity prattices'es.theY relate to thisAgreement, including Without limitation, accesato,a.ny security assesmentrepprtS designed to be shared with third parties. Any information documentationprovided pursuant to this assessment process Or otherwise pirrsuant to this .SChedule .shall be considered CrowdStrike's Confidential Information and subject to the Confidentiality section of the Agreement CrOwcjEitrilie FellT(1 May 27 2919 12 of 17 7. •Customer 0. blioations. Customer, along with its Affiliates, represents and warrants that: (i) it owns dr haS right of use from e third party,.and controls, directly or indirectly, all of the software hardware and computer systems:(collectively, "Systems')wl icrL the;Produrts and/or CrowdStrike Tools will=be installed or that will be th subject of; or investigated durinq,.the Offerings, (ii) to the extent required under:any federal,,state, or loc_ii.t.i & or non-OS aws(e.g,;Computer fraud and Abuse:Act, '�l�,S:C.: '1 00 et scq., Title ill 1a ►!: .C. 2510-et and the Electronic'Communications Privacy .Act, 18 U.S.C: § 2701 Pt s+fir.) it has autJ'rorized•Crowd Strike to access the Systenms and process and transmit data,through the Offerrrigs and CrotwdStrike Tools in accrr 1—irice with this..Agreeme;,t and as necessary to Orovlde rand perform th+.•OfferErrrgs. (iru'it has a•lawful.basis in having CrowdStrike investigate tie Systerns, process the Customer Diata and the Personal Data; (tit).that it is rnd.,,rill at all relevant times remainr:luly and effectively authorized to instruct CroWdStrike tcs carry out the Offerings,anc.'•(:) it has made all necessary disclosures, obtained all necessary ci:tnsents and..government authorizations required undoi-appticahle,law•tu,permit the professing and international transfer of Customer Data and Custom-Personal Data from each Customer.and-.Customer Affiliate; to.Cr'owdStrike.. 8.: Notices. The following individuals, shall be the primary cdntects at Customer and Crowd Strike for any coordination; communications or neticcs with reepect to Personal Data and:this Schedule: a, crowdStrike: Drew Bagley,VP&Counsel, Privacy&Cyber Policy(dz'ew bag€eyOcrowdstr=ikre.com with-a copy to leuel z,crowdstrike:cc,rr:). For any Security Breach: Jerry Dixon, Chief lr rf+tirrriatior: Security Officer errs.dixon@cr'owdstrike.corn With a copy to secjrity(eacrc vdstrike.conil, b. Customer.the personwho has_:signed the Agreement or another persori.as otherwise designate(:in•wr;itirig (including by'email)-by Customer to CrowdStrike. Each party shall proinotiy notify tha other if any.of he' feregaing.contact info rrriation changer: • I.fQN:dSrfl?(a.r'>~erfl: •stay 2i 2C�13. 13•of 17