Security Addendum
This Security Addendum forms part of the Terms between you and TITLEMAN Inc. Capitalized terms not defined herein have the meanings set forth in the Terms. The Service is provided using cloud-based infrastructure operated by TITLEMAN Inc and/or its service providers (the “Cloud Environment”).
1. SECURITY PRACTICES
- 1.1. TITLEMAN Inc applies generally accepted industry practices designed to support the security of the Service and the protection of Customer Data and Content.
- 1.2. Information regarding our security practices may be made available to customers upon reasonable request, subject to appropriate limitations.
- 1.3. TITLEMAN Inc may update or modify its security approaches and frameworks from time to time to reflect evolving industry standards and operational needs.
2. DATA STORAGE AND PROCESSING
- 2.1. Customer Data and Content are stored and processed by TITLEMAN Inc and/or its service providers in data centers located in agreed geographic regions.
- 2.2. Requests to store Customer Data and Content in alternative geographic regions may be considered, subject to technical feasibility and compliance with applicable laws and regulations.
3. DATA PROTECTION MEASURES
- 3.1. TITLEMAN Inc implements reasonable technical and organizational measures intended to protect Customer Data and Content against unauthorized access, disclosure, alteration, or loss.
4. SYSTEM ACCESS AND SECURITY
- 4.1. Access to systems used to provide the Service is limited to personnel who require such access for legitimate business purposes.
- 4.2. Personnel may access Customer Data or Content only as necessary to provide or support the Service, or as otherwise required by applicable law.
- 4.3. TITLEMAN Inc uses standard monitoring and protective measures designed to identify and respond to potential security risks affecting the Service.
- 4.4. Security testing and reviews may be conducted periodically at TITLEMAN Inc’s discretion.
5. ADMINISTRATIVE MEASURES
- 5.1. TITLEMAN Inc maintains internal policies and procedures intended to promote security awareness and responsible handling of data by personnel.
- 5.2. Personnel are required to comply with confidentiality obligations and applicable internal security policies.
- 5.3. Access rights are reviewed and adjusted in connection with role changes or termination of personnel.
6. VENDORS AND SERVICE PROVIDERS
- 6.1. TITLEMAN Inc seeks to engage vendors and service providers that apply security measures generally consistent with those used by TITLEMAN Inc.
- 6.2. Information regarding service providers may be updated from time to time.
7. PHYSICAL SECURITY
- 7.1. The Cloud Environment is hosted in data centers that employ standard physical security controls commonly used in the industry.
- 7.2. Customer Data and Content are not stored or hosted in TITLEMAN Inc office locations.
8. SECURITY INCIDENTS
- 8.1. If TITLEMAN Inc becomes aware of a security incident that may materially affect Customer Data or Content, it will notify the customer within a reasonable timeframe.
- 8.2. TITLEMAN Inc will take reasonable steps to investigate and mitigate the effects of such incidents.
9. LOGGING AND MONITORING
- 9.1. TITLEMAN Inc may maintain system logs and records as reasonably necessary to support the operation, reliability, and security of the Service.
10. CUSTOMER INQUIRIES
- 10.1. Upon reasonable request, TITLEMAN Inc may provide general information regarding its security practices, subject to confidentiality and security considerations.
11. CUSTOMER RESPONSIBILITIES
- 11.1. Customer responsibilities regarding authorized use of data, access credentials, and system security are described in the Terms and remain the customer’s responsibility.
12. BUSINESS CONTINUITY
- 12.1. TITLEMAN Inc maintains reasonable measures intended to support service continuity and recovery in the event of disruptions.
