These Lendscape Platform Terms form part of the Agreement entered into between Lendscape and the Customer.
1. Definitions and interpretation
1.1. In this Agreement, the capitalized terms below have the following meanings:
Acceptance means the acceptance of a Deliverable by the Customer in accordance with the acceptance process set out in the relevant SOW (or failing such specific process being agreed, the process set out in Schedule 1).
Affiliate means with respect to either Party, any entity that directly or indirectly is controlled by, controls, or is under common control with another party.
Agreement has the meaning given to it in the Order Form.
Applicable Laws means all laws and regulations, and any binding regulatory policies, guidelines, and rules applicable to the activities of the relevant Party.
Business Hour means, unless otherwise set out in the Order Form, an hour between 9am and 5.30pm (in Lakeland, Florida) within a Working Day.
Change means any change to the Services, or the Platform provided under this Agreement.
Change Control Procedure means the process to manage and agree a Change, as set out in Schedule 4.
Charges means the fees and charges payable by the Customer to Lendscape for the Platform and Services as set out in the Order Form and any Statement of Work, and any additional fees and expenses that may be charged in accordance with the terms of this Agreement.
Confidential Information means such information as either Party may from time to time provide to the other Party relating to the Services and performance under this Agreement and all know-how, trade secrets, tactical, scientific, statistical, financial, commercial or technical information of any kind disclosed by either Party to the other whether in existence prior to the Parties entering into this Agreement or which subsequently comes into existence, and in respect of Lendscape includes the terms of this Agreement (including commercial and pricing terms) and any information contained in the Lendscape Materials, and in respect of the Customer includes the Customer Data.
Contract Year means each 12-month period from the Effective Date.
Customer means the entity set out in the Order Form.
Customer Data means the data inputted into the information fields of the Platform by the Customer Group and their Users by way of manual entry, file upload or use of Lendscape’s APIs.
Customer Dependencies: means the Customer’s compliance with this Agreement and the specific dependencies on the Customer (or Customer Group) for Lendscape to perform the Services, as set out in, or referenced in, the Order Form, Clause 6 or an individual SOW.
Customer Group means the Customer and any Affiliate of the Customer specifically listed (if any) in the Order Form as being entitled to use the Platform, and in each case for so long as such company remains an Affiliate of the Customer.
Customer Materials means any data (including Customer Data), information, or other material provided to Lendscape by, or on behalf of, the Customer Group or Users for the performance of this Agreement, excluding any Lendscape Materials and any Intellectual Property Rights owned by Lendscape or its licensors.
Customer Security Controls and Fair Use Policy means Lendscape’s policy on security and accepted and prohibited use of the Platform, as set out on the Lendscape Trust Centre;
Customer Systems has the meaning given to it in clause 11.2.
Deliverable means any work product listed as such in the Order Form or Statement of Work.
Documentation: the operating manuals, user instruction manuals, technical literature and all other related materials in human-readable or machine-readable forms in relation to the Services as supplied and updated by Lendscape from time to time.
Early Termination Fee means an amount equal to (i) 75% of the remaining Charges payable in the 12 months following termination and (ii) 50% of the remaining Charges (after such 12 month period) to the end of the Initial Term or (if applicable) the then committed renewal term.
Effective Date means the date set out in the Order Form.
Enhancement means any replacement, modification, upgrade, enhancement, or addition to the functionality of the Platform, implemented at the Customer’s cost and request under a SOW.
Escalation Procedure means the dispute resolution procedure set out in Schedule 4.
Exit Period means the period from the date on which a notice to terminate is served to the date on which the Parties (acting reasonably) agree that the exit and migration exercise has been completed, which may be a period of up to (but not exceeding) 12 months if required by the Customer.
Force Majeure Event means an event or sequence of events which is beyond a Party’s reasonable control and which prevents or delays it performing its obligations under this Agreement (provided that an inability to pay is not a Force Majeure Event), including an act of God, or any matters relating to transfer of data over the internet or communications networks, and any delays or problems associated with any such networks or any utility services or the internet.
Good Industry Practice means the degree of professionalism, skill, and diligence which would be expected from a company engaged in the same type of activity under the same or similar circumstances.
Implementation SOW has the meaning given to it in clause 5.1.
Improvement means any change, improvement, development, enhancement, modification or derivative in or relating to the Platform, including in any Enhancement or Release.
Incident means an unplanned interruption to the production instance of the Platform or failure of the production instance of the Platform to perform in accordance with the Documentation (but excluding any issue outside of Lendscape’s control), as further detailed in Schedule 3.
Incident Management Process means the process for handling Incidents, as set out in Schedule 3.
Initial Term means the initial subscription term, as set out in the Order Form.
Intellectual Property Rights means patents, rights to inventions, copyright and related rights, moral rights, trademarks and service marks, business names and domain names, rights in get-up, goodwill, rights in designs, rights in computer software, database rights, rights to use and protect the confidentiality of Confidential Information (including know-how and trade secrets), and all other intellectual property rights, whether registered or unregistered and including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim priority from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world.
Lendscape Materials means any data, information, or other material provided by or on behalf of Lendscape in the course of providing the Platform and Services, including the Documentation and all know-how developed in the provision of the Platform Services.
Lendscape Hourly Rate means the applicable rates set out in the Order Form.
Lendscape Trust Centre means the online resource that provides customers and stakeholders access to Lendscape’s latest compliance documentation, security certifications and attestations, key policies, and reports,.available at https://app.conveyor.com/profile/lendscape/.
Managed Services means the provision of the Platform and associated managed services as set out in Schedule 1.
Module has the meaning given to it in the Order Form (and being a module of functionality in the Platform subscribed to by the Customer).
Order Form: means the order form signed by Lendscape and the Customer, which sets out the commercial details applicable to the Customer, including details of the Charges.
Output Report means any documentation or report that is produced for the Customer Group as an output of the Platform based on Customer Data.
Platform has the meaning given to it in the Order Form, and includes the software, infrastructure and environments provided and managed by Lendscape, including any Improvements.
Project(s) means a package of services to be performed by Lendscape, as described in a Statement of Work entered into by the Parties.
Release means any new enhanced version of the Platform made available by Lendscape from time to time (as designated by Lendscape), and which is not just an interim Update.
Sales Tax means all sales, use, excise, gross receipt, and similar transaction tax, or equivalent taxes.
Service Credits means the credits which become due to the Customer if the Service Levels are not achieved as set out in Schedule 2.
Service Levels means the service levels set out in Schedule 2.
Services means the services provided by Lendscape under this Agreement (including the provision of the Managed Services and the ongoing Support Services), and any new services added during the term of this Agreement in any Statement of Work or supplemental Order Form.
Statement of Work or “SOW” means a document detailing the scope, deliverables and plan for a particular Project agreed between the Parties in accordance with clause 5.
Subscription Fee means the annual fee for the provision of the Platform and associated Support Services, calculated in accordance with the Order Form.
Support Services means those services to resolve Incidents and support the provision of the production instance of the Platform, as set out in Schedule 3.
Term means the Initial Term, and each agreed renewal period and/or Renewal Term (if any), and any Exit Period.
Update means patches, mitigations, bug fixes, enhancements, or other updates for functionality, availability, stability or security reasons for the Platform or underlying infrastructure.
Usage Data means information, data and statistics on how the Platform is used and interacted with by Users, such as the number of users, extractors and connectors, data storage capacity used, the number or value of assets or funds, user click throughs on the Platform, and volume and traffic on the Platform.
Users means any employee or other staff of the Customer or the Customer Group.
Virus: means any thing or device (including any software, code, file or program) which may:
a) prevent, impair or otherwise adversely affect the operation of any computer software, hardware or network, any telecommunications service, equipment or network or any other service or device;
b) prevent, impair or otherwise adversely affect access to or the operation of any program or data, including the reliability of any program or data (whether by re-arranging, altering or erasing the program or data in whole or part or otherwise); or
c) adversely affect the user experience, including worms, trojan horses, viruses and other similar things or devices.
Working Day means, unless otherwise set out in the Order Form, Monday to Friday, except for U.S. federal public holidays.
1.2. The following rules of interpretation shall apply to this Agreement:
1.2.1. A reference to a holding company shall mean, with respect to a specified entity, any other entity that Controls the specified entity. A reference to a “subsidiary” shall mean, with respect to a specified entity, any other entity that is Controlled by the specified entity. As used herein, “Control” means, with respect to any entity, (a) direct or indirect ownership of more than fifty percent (50%) of the voting interests of such entity; (b) the right to elect or appoint a majority of the members of the board of directors or other governing body of such entity; or (c) the power, whether by ownership, contract, or otherwise, to direct or cause the direction of the management and policies of such entity. “Controlled” and “under common Control” have correlative meanings.
1.2.2. Unless the context otherwise requires, words in the singular shall include the plural and in the plural shall include the singular. Headings do not affect the interpretation of this Agreement.
1.2.3. Any words following the terms including, include, in particular, for example or any similar expression shall be interpreted as illustrative and shall not limit the sense of the words preceding those terms.
1.2.4. A reference to a particular law is a reference to it as it is in force for the time being taking account of any amendment, extension, application or re-enactment, and includes any subordinate legislation for the time being in force made under it.
1.2.5. Except where a contrary intention appears, a reference to a clause, schedule or annex is a reference to a clause of, or schedule or annex to, this Agreement.
1.2.6. Any reference to an hour of the day or day of the week shall be taken to be a reference to an hour of the day or day of the week in Lakeland, Florida.
1.2.7. Anything required in writing excludes fax, but includes email.
1.2.8. References to “use in production”, “production use”, “production version” or similar terminology means the live operation of the Platform for the purpose of the day to day running of the Customer Group’s businesses (and does not include any non-production, recovery, or test environment).
2. The Platform and Services
2.1. Subject to and in accordance with the terms of this Agreement, and in consideration for payment of the Charges, Lendscape shall make the Platform available to the Customer, and shall provide the Services to the Customer during the Term. Lendscape acknowledges that members of the Customer Group may use the Platform, and clause 25 sets out the terms on which this Agreement applies to the Customer Group.
2.2. Lendscape shall provide to the Customer, from time to time, copies of the Documentation containing up-to-date information for the proper use of Platform. Such Documentation may be supplied in electronic form.
2.3. Whilst Lendscape does not warrant that the Platform will be uninterrupted or error-free, Lendscape shall:
2.3.1. ensure that the Platform will perform materially in accordance with the functionality described in the Documentation in all material respects;
2.3.2. perform the Services with reasonable care and skill and in accordance with Good Industry Practice; and
2.3.3. use up-to-date malware protection techniques and appropriate technical and organizational measures, in accordance with Good Industry Practice to seek to protect against the introduction of any Viruses, including such measures as set out in the Customer Security Controls and Fair Use Policy,
and any failure or non-conformity shall be dealt with by Lendscape through the Support Services.
2.4. The Customer acknowledges and agrees that:
2.4.1. the Platform is not being made available to meet the Customer Group’s individual requirements and that it is therefore the Customer’s responsibility to ensure that the facilities and functions available in the Platform are fit for the desired purpose and meet the Customer Group’s individual requirements;
2.4.2. it is responsible for its use and its Users’ use of the Platform and that Lendscape bears no responsibility to the Customer for the services that the Customer supplies to its third parties, customers or their end customers; and
2.4.3. Lendscape shall not be responsible for:
2.4.3.1. non-conformance with clause 2.3 to the extent caused by use of the Platform contrary to Lendscape’s instructions, or by any modification or alteration to the Platform by any person other than Lendscape or Lendscape’s duly authorized contractors or agents; and
2.4.3.2. failures or delay in transmission of data or information caused by the internet or by any communications or other software or hardware systems outside of any communications facilities forming part of the Platform or Services.
3. Acceptance and new Releases
3.1. The first implementation of the Platform and (unless otherwise agreed between the Parties in writing) each subsequent Enhancement or Release shall undergo Acceptance by the Customer. The acceptance criteria shall be agreed by the Parties acting reasonably by reference to the Documentation and specification in the relevant SOW and using Good Industry Practice. Once Acceptance has been achieved it cannot later be rejected and any Incidents should be resolved through the Support Services.
3.2. Lendscape may make available new Releases of the Platform from time to time and the Customer agrees to the implementation of such Releases in accordance with the process set out in Schedule 1.
4. Service Levels
4.1. Lendscape shall provide the Platform in accordance with the Service Levels and shall provide the Support Services to resolve any Incidents.
4.2. Where any target timetable for the performance of the Services or set-up of the Platform is set out in the Order Form or otherwise agreed between the Parties (including in any SOW), the Customer acknowledges that any date or timescale is an estimate only (and may be dependent on certain Customer Dependencies).
4.3. Where any Service Credit (or other form of liquidated damage) is payable by Lendscape under this Agreement, such amount shall be the Customer’s sole and exclusive remedy in respect of any such issue that gave rise to such amount being due as a credit or payment, save if the Customer terminates this Agreement for material breach pursuant to clause 16.3.
5. Statements of Work
5.1. An initial SOW shall be entered into by the Parties for the initial implementation and configuration of the Platform for the Customer (“Implementation SOW”). The Implementation SOW shall set out, amongst other detail: the scope, assumptions, deliverables, and charges, the acceptance and testing process, and the estimated timetable and target date for the Platform go-live in production use.
5.2. If the Parties agree to implement any Projects for Enhancements to the Platform or additional Services, the parties shall mutually agree a SOW. The SOW shall:
5.2.1. set out in detail the Project to be delivered by Lendscape (the contents of which will vary depending on the nature of the Project and tasks required within it, but will set out the relevant scope, timetable, and Charges);
5.2.2. be negotiated in good faith between the Parties with a view to agreeing the applicable SOW as soon as reasonably practicable; and
5.2.3. once signed by the Parties, become incorporated into this Agreement and come into force on the date set out in the applicable SOW.
5.3. Lendscape shall provide the Services and Deliverables set out in the SOW using reasonable skill and care, and shall use its reasonable endeavors to meet any performance dates specified therein (or if no performance dates are specified, shall perform the Services within a reasonable time), but any such dates shall be estimates only.
5.4. Once a SOW is entered into, Lendscape will commit resources to provide the relevant Services, and so the Services under the SOW cannot be terminated unless specifically provided in that SOW.
6. Customer obligations
6.1. The Customer shall devote such resources and management time as are necessary to meet or otherwise comply with the Customer Dependencies under this Agreement in a timely and efficient manner, and shall procure the same from the Customer Group. In particular, the Customer shall, at its own expense:
6.1.1. provide to Lendscape all necessary cooperation, assistance, data, information, documents and instructions as well as access to agreed premises and facilities as Lendscape may reasonably request for the implementation of the Platform and provision of the Services;
6.1.2. ensure that in the interests of health and safety, Lendscape’s personnel, while on the Customer Group’s premises for the purposes of this Agreement, are provided with information and training to ensure they are familiar with relevant safety procedures;
6.1.3. ensure that its agents and sub-contractors and members of the Customer Group cooperate fully with Lendscape as reasonably required in relation to the performance of this Agreement; and
6.1.4. ensure that each of the Users who access the Platform adhere to and follow the terms of this Agreement.
6.2. The Customer accepts that it, and relevant members of the Customer Group, are responsible for (and Lendscape has no liability in respect of):
6.2.1. providing and maintaining the necessary hardware, operating system software, telecommunications links and browser software to access the Platform and receive the Services;
6.2.2. maintaining appropriate levels of security for all systems connected with the Platform, being at least in accordance with the Customer Security Controls and Fair Use Policy;
6.2.3. ensuring Users use the Platform in accordance with the Documentation, the Customer Security Controls and Fair Use Policy, and with any reasonable instructions given by Lendscape; and
6.2.4. using reasonable endeavors to check the results of the processing of the Customer Data using the Platform to ensure such processing is being carried out correctly.
6.3. The Customer acknowledges and agrees that Lendscape shall not be responsible for any delay or failure to provide the Platform or perform the Services in accordance with this Agreement where such delay or failure has resulted from the Customer failing to provide, procure or meet the Customer Dependencies in a timely and efficient manner. Where such delay or failure arises, Lendscape shall be entitled to:
6.3.1. adjust any timetable or delivery targets set out in this Agreement as reasonably necessary; and
6.3.2. charge the Customer for any additional time and materials reasonably incurred by Lendscape as a result of such Customer failure, provided that Lendscape notifies the Customer in advance and uses its reasonable endeavors to mitigate the same.
7. Legal & regulatory obligations
7.1. In performing their obligations under this Agreement, each Party must comply with all Applicable Laws and the Customer shall procure the same from the Customer Group and all Users.
7.2. It is acknowledged by the Parties that:
7.2.1. each of the Parties shall maintain such authorizations and/or other approvals as may be required from time to time in connection with the performance of its obligations under this Agreement;
7.2.2. where the Platform is facilitating compliance with legal or regulatory requirements applicable to the Customer Group, as between the Parties the Customer shall be wholly responsible for ensuring the Platform content and configuration is fully compliant with Applicable Law; and
7.2.3. neither Party has, or is, providing the other with legal, tax or regulatory advice.
7.3. The Regulatory Addendum in the Online Schedules (Regulatory Addendum) sets out additional rights and obligations of the Parties under this Agreement in respect of certain legal and regulatory requirements applicable to the Customer and the Customer Group.
8. Change Control Procedure
8.1. Either the Customer or Lendscape may request a Change to the Platform, the Services or any of the terms of this Agreement. Any such Change will be discussed and documented (where agreed) pursuant to the Change Control Procedure in Schedule 4.
8.2. The Customer is responsible for coordinating any Change with any other member of the Customer Group.
9. Charges
9.1. The Charges shall be calculated and paid by the Customer to Lendscape in accordance with this clause 9. and the Order Form or relevant Statement of Work. All Charges are subject to Sales Tax which shall be payable by the Customer at the applicable rate prescribed by law.
9.2. As regards all Charges in this Agreement, Lendscape may on each anniversary of the Commencement Date increase any or all such Charges by an amount equal to the US Consumer Price Index (CPI-U) for the preceding January, plus an additional 2%, or, having provided reasonable justification and subject to the agreement of the Customer acting reasonably, a greater amount. Any such increase shall take effect on the anniversary of the Commencement Date each year and Lendscape shall notify the Customer of such increases at least 30 (thirty) days in advance of the increase taking effect. If the CPI-U should be abolished or substantially changed, Lendscape may at any time by written notice substitute such other index as most closely resembles the CPI-U before its abolition or change. If the CPI-U is a negative amount, a base of 0% shall be used as the CPI-U.
9.3. Where the Charges under a SOW are on a time and materials basis, Lendscape will inform the Customer as soon as Lendscape has reason to believe that the cost estimate has been exceeded or is likely to be exceeded by ten per cent or more and will, at the Customer’s request, submit a revised cost estimate to the Customer for its approval. Lendscape will advise the Customer on a monthly basis of the time taken to date and the estimated time to complete in relation to the cost estimate.
9.4. Save as otherwise set out in the Order Form or relevant Statement of Work, all invoices must be paid in full without deduction or set-off, in cleared funds, within 30 calendar days from the date of issue of the invoice.
9.5. The Customer accepts that:
9.5.1. all Charges are payable whether or not the Customer Group makes any use of the Platform during any specified period for which a Charge relates; and
9.5.2. if any withholding is required by law, the Customer shall gross up such amount so that the net payment to Lendscape equals the amount Lendscape would receive without such withholding.
9.6. Subject to clause 9.7, Lendscape reserves the right to charge interest on any overdue Charges at 4% per annum above the 1-month term Secured Overnight Financing Rate (SOFR) from time to time, which shall accrue daily and be compounded quarterly, and apply from the due date for payment until actual payment in full, whether before or after judgement.
9.7. If the Customer has any bona fide dispute in relation to any Charges due, then:
9.7.1. it shall notify Lendscape promptly of the nature of the dispute and the disputed amount, and the Parties shall follow the Escalation Procedure to resolve the dispute;
9.7.2. Lendscape shall cancel its original invoice and raise an invoice for the undisputed amount (which shall be payable in accordance with clause 9.4); and
9.7.3. once the dispute has been resolved, Lendscape shall issue an invoice for the agreed amount plus interest accruing under clause 9.6 from the original due date, and the Customer shall pay such invoice within seven days of receipt.
10. Data Protection and security
10.1. The Parties shall comply with the Data Protection Agreement set out in the Online Schedules (Data Protection Agreement), and Lendscape shall implement security measures for the Platform as set out in the Customer Security Controls and Fair Use Policy.
11. Customer Data and Customer Systems
11.1. As between the Parties, the Customer or relevant member of the Customer Group (as the case may be) owns and shall retain all Intellectual Property Rights in the Customer Systems and Customer Data. The Customer is responsible for the availability, accuracy and completeness of the Customer Data.
11.2. The Parties acknowledge that the Platform may interact, link, inter-operate, interface with or otherwise utilize, whether directly or indirectly, certain software, application interfaces, data feeds or exchanges and systems used by or on behalf of the Customer Group (“Customer Systems”). The Customer is responsible for the availability, interoperability and any input from the Customer Systems.
11.3. The Customer hereby grants to Lendscape a right to use, copy and otherwise utilize the Customer Data and interact, link, inter-operate, interface with Customer Systems to the extent required to provide the Services and exercise any obligations set out in this Agreement. Lendscape may sublicense this right to its permitted sub-contractors, only to the extent they required use of or access to the same to assist in the provision of the Platform or Services.
11.4. Lendscape may monitor and collect Usage Data on the use and performance of the Services and to detect threats or errors to the Platform and/or Lendscape’s operations. Lendscape may also use Usage Data for the purposes of the further development and improvement of Lendscape’s services, provided such information does not directly identify the Customer Group, any Users or the Customer Data.
12. Confidentiality
12.1. Each Party shall treat as confidential all Confidential Information of the other Party and its Affiliates supplied or made available under this Agreement and shall:
12.1.1. protect the Confidential Information using reasonable technical and organizational measures not less protective than those that it uses in respect of its own Confidential Information;
12.1.2. not use the Confidential Information of the other Party and its Affiliates otherwise than in the exercise and performance of its rights and obligations under this Agreement;
12.1.3. not share any such Confidential Information with any person, except to its own employees and staff and those of its permitted subcontractors (and then only to those persons or third parties who need to know it for the performance of this Agreement and who are subject to binding obligations of confidentiality materially equivalent to this clause 12).
12.2. The restrictions imposed by clause 12.1 shall not apply to the disclosure of any Confidential Information which:
12.2.1. is now in, or hereafter comes into, the public domain otherwise than as a result of a breach of this clause 12;
12.2.2. is in the receiving Party’s lawful possession and was obtained or acquired in circumstances under which the receiving Party was (or its Affiliates were) not bound by any form of confidentiality obligation;
12.2.3. is independently developed by the receiving Party, which independent development can be shown by written evidence; or
12.2.4. is required by law or regulation to be disclosed to any person who is authorized by law or regulation to receive the same (after consultation, if practicable, with the disclosing Party to limit disclosure to such authorized person to the extent necessary).
12.3. Where a Party is required to disclose the other Party’s Confidential Information pursuant to clause 12.2.412.2.3, it shall unless prevented by law or a regulatory authority, first notify that other Party of any such requirement and take reasonable steps to prevent or limit such disclosure within Applicable Law.
12.4. The Customer shall ensure that all Users are at all times made aware that Lendscape’s Confidential Information is confidential.
12.5. In the event of unauthorized disclosure of Confidential Information, the receiving Party shall notify the disclosing Party without undue delay and take all necessary steps to mitigate the impact of the disclosure. The receiving Party shall also provide a written explanation of the disclosure and cooperate with the other Party to prevent future unauthorized disclosures.
13. Intellectual property
13.1. All Intellectual Property Rights in and to the Services, Platform and Lendscape Materials (including the look and feel of any Output Reports) shall vest and remain vested in Lendscape and except as expressly set out in this Agreement, neither the Customer nor any member of the Customer Group or any User shall acquire any right, title or interest in or to the Intellectual Property Rights of Lendscape or its licensors.
13.2. Subject to the terms of this Agreement, Lendscape hereby grants to the Customer during the term of this Agreement, a limited, worldwide, non-exclusive, non-sublicensable license for use of and access to the Platform, and a right to permit members of the Customer Group and Users to access and use the Platform during the Term. Lendscape hereby grants the Customer a perpetual license to use any of its Intellectual Property Rights in the Output Reports in the form produced by the Platform for its internal business purposes.
13.3. The Customer or its relevant third-party licensors own all Intellectual Property Rights in and to the Customer Materials. Except as expressly stated herein, this Agreement does not grant Lendscape any rights to, or in, any Intellectual Property Rights in respect of the Customer Materials and all such rights are expressly reserved to the Customer or its third-party licensors.
13.4. The Customer hereby grants Lendscape a non-exclusive, royalty-free license to use the Customer Materials for the purpose of providing the Services and Platform. Lendscape may sublicense this right to its permitted sub-contractors, only to the extent they require use of or access to the same to assist in the provision of the Platform or Services.
13.5. Lendscape may use any feedback or suggestions for Improvement relating to the Services or the Platform provided by the Customer Group or any Users without charge or limitation. Unless otherwise specified in a SOW, any Enhancement may be implemented into the development roadmap for the Platform and the functionality may be made available to other customers of Lendscape.
14. IP Indemnity
14.1. Lendscape shall indemnify and defend the Customer against any losses, claims, damages, or reasonable costs or expenses arising out of or in connection with any claim that the use of the Platform or receipt of the Services in accordance with this Agreement, infringes a third party’s Intellectual Property Rights (Claim). If any third party makes a Claim, or notifies an intention to make a Claim, which may reasonably be considered likely to give rise to a liability under this indemnity, the Customer shall:
14.1.1. as soon as reasonably practicable, give written notice of the Claim to Lendscape, specifying the nature of the Claim in reasonable detail;
14.1.2. give Lendscape sole conduct of the Claim;
14.1.3. not make any admission of liability, agreement or compromise in relation to the Claim without the prior written consent of Lendscape (such consent not to be unreasonably conditioned, withheld or delayed);
14.1.4. give Lendscape and its professional advisers access at reasonable times (on reasonable prior notice and at Lendscape’s reasonable cost) to its officers, directors, employees, agents, representatives or advisers, and to any relevant documents and records within the power or control of the Customer Group, for the purpose of assessing and defending the Claim; and
14.1.5. take such action, at Lendscape’s reasonable cost, as Lendscape may reasonably request to avoid, dispute, compromise or defend the Claim (and which may include implementing an Update or Release to remove or remediate the infringing Intellectual Property Rights).
14.2. The Customer shall indemnify and defend Lendscape against any losses, claims, damages, or reasonable costs or expenses arising out of or in connection with any claim that Lendscape’s (or its permitted sub-licensees) receipt or use of the Customer Materials or Customer Systems infringes a third party’s Intellectual Property Rights (Claim). If any third party makes a Claim, or notifies an intention to make a Claim, which may reasonably be considered likely to give rise to a liability under this indemnity, Lendscape shall:
14.2.1. as soon as reasonably practicable, give written notice of the Claim to the Customer, specifying the nature of the Claim in reasonable detail;
14.2.2. give the Customer sole conduct of the Claim;
14.2.3. not make any admission of liability, agreement or compromise in relation to the Claim without the prior written consent of the Customer (such consent not to be unreasonably conditioned, withheld or delayed);
14.2.4. give the Customer and its professional advisers access at reasonable times (on reasonable prior notice and at the Customer’s reasonable cost) to its officers, directors, employees, agents, representatives or advisers, and to any relevant documents and records within the power or control of Lendscape, for the purpose of assessing and defending the Claim; and
14.2.5. take such action, at the Customer’s reasonable cost, as the Customer may reasonably request to avoid, dispute, compromise or defend the Claim.
15. Suspension
15.1. Lendscape may temporarily suspend access to the Platform and the provision of the Services (in whole or in part) on advance notice (or immediately in an emergency to protect the Customer or Lendscape from any adverse effects) if:
15.1.1. the Platform is used in breach of this Agreement (including any breach of the Fair Use and Storage Limits set out in the Order Form and/or the Customer Security Controls and Fair Use Policy) and such misuse (i) could have a material impact on Lendscape or the hosting environment and (ii) is not remedied within a reasonable period as notified by Lendscape;
15.1.2. save in the case of a bona fide dispute, the Customer fails to pay any sums due to Lendscape by the due date for payment, and such failure to make payment is not remedied within 30 days of written request from Lendscape; or
15.1.3. required by Applicable Laws, or by any court or governmental or regulatory order.
15.2. Where the reason for the suspension is the misuse of the Platform, Lendscape shall restore access promptly after the issue has been resolved. Where the reason for the suspension is non-payment, access to the Platform shall be restored promptly after Lendscape receives payment in full in cleared funds.
16. Term and termination
16.1. This Agreement shall commence on the Effective Date and shall continue for the Initial Term, unless otherwise terminated as provided in this clause 16. After the Initial Term, the Agreement shall automatically renew for consecutive three-yearly periods (each a “Renewal Term”), unless either Lendscape or the Customer notifies the other, in writing, at least 90 days before the end of the Initial Term or the then current Renewal Term, of its decision to terminate.
16.2. Each SOW shall continue for its stated term, or if no express term is stated until the Project has been completed. The expiry or termination of an individual SOW shall not operate to terminate this Agreement or any other SOW in existence at that time.
16.3. Either Party may terminate this Agreement on 30 days’ written notice to the other Party if:
16.3.1. the other Party commits a material breach of this Agreement and such breach is not remediable;
16.3.2. the other Party commits a material breach of this Agreement which is not remedied within 30 days of receiving written notice from the non-breaching Party of such breach;
16.3.3. the other Party has failed to pay any amount due under this Agreement within 30 days of the due date and such amount remains unpaid within 30 days after the other Party has received notification from the non-defaulting Party that such payment is overdue; or
16.3.4. if any specific termination event as provided in this Agreement (including as set out in Schedule 5) occurs.
17. Effect of expiry or termination
17.1. Without prejudice to any specific provisions elsewhere in this Agreement, on the expiry or termination of this Agreement:
17.1.1. the Customer shall pay all outstanding Charges and reimburse Lendscape on demand for any deferred or unrecovered amortized Charges;
17.1.2. where Lendscape has terminated pursuant to clause 16.3 (or the Early Termination Fee is otherwise expressed to be payable by the Customer pursuant to this Agreement), the Customer shall pay Lendscape the Early Termination Fee;
17.1.3. Lendscape shall provide the continuity and exit support set out in Paragraph 12 of Schedule 5 during the Exit Period;
17.1.4. save to the extent required during the Exit Period:
a) save for accrued rights or liabilities that shall continue, all rights and obligations of the Parties, including access to and use of the Platform, shall immediately terminate;
b) the Customer shall promptly return to Lendscape (or otherwise delete or dispose of as Lendscape may instruct) all property belonging to Lendscape and all copies of the Documentation; and
c) both Parties shall return (or otherwise delete or dispose of as the other Party may instruct) the other Party’s Confidential Information and shall, if requested, provide written confirmation to the other Party of such deletion or disposal; and
17.1.5. the following clauses shall survive and continue in full force and effect following termination: 9, 12, 13, 14, 17, 18, and 21 – 30, together with any other provision intended to have effect.
17.2. Within 90 days following termination or expiry of the Agreement (or if later, 90 days following expiry of the Exit Period), the Customer may request a copy of the Customer Data contained in the production environment of the Platform and Lendscape shall provide a copy of such Customer Data as soon as reasonably practicable in such format as is agreed or, in default of agreement, in such format as is generally used in the market at the time of termination. If the Customer fails to request the Customer Data within such 90-day period, Lendscape may delete it without prior notice.
17.3. If the Customer (for itself or the Customer Group) requires any further assistance, such as migrating any Customer Data to a new environment, or with interpreting or re-formatting its data, or extracting or migrating data, or providing database schemas or other materials or information to assist with any of the foregoing, Lendscape shall agree to do so at the Customer’s reasonable cost, subject to the Parties agreeing a SOW in respect of the scope and charges for such work.
18. Limitation of liability
18.1. Notwithstanding any other provision of this Agreement, the liability of the Parties shall not be limited in any way in relation to:
18.1.1. death or personal injury caused by its or its subcontractor’s negligence;
18.1.2. its fraud, fraudulent misrepresentation or theft;
18.1.3. in respect of the Customer, infringement of Lendscape’s Intellectual Property Rights or non-payment of the Charges; or
18.1.4. any other losses which cannot be excluded or limited by applicable law.
18.2. Neither Party shall be liable to the other for any special, incidental, punitive consequential, or indirect loss or damages, or for any (whether direct or indirect) (i) loss of profit, revenues, or actual or anticipated savings; (ii) loss of business, contracts, goods or opportunity; (ii) loss of or damage to equipment or loss of use or production; or (iv) depletion of goodwill or harm to reputation.
18.3. Save for any liability falling under clause 18.4, the aggregate liability of each Party under this Agreement to the other Party for any losses, claims, damages, costs or expenses arising out of or in connection with this Agreement, or any agreement collateral to this Agreement, in any circumstances, whether in contract, tort or in any other way and whether or not caused by negligence or misrepresentation, shall not exceed the greater of (i) $100,000 and (ii) the amount of the Subscription Fee billed and paid by the Customer to Lendscape in the 12-month period immediately preceding the date the first event or circumstance giving rise to the liability took place or began.
18.4. The parties accept that:
18.4.1. the liability of Lendscape under clauses 12 and 14.1 shall be limited in the aggregate to $5,000,000;
18.4.2. the liability of the Customer under clauses 12 and 14.2 shall be limited in the aggregate to $5,000,000.
18.5. Lendscape shall not be liable under this Agreement to the extent liability arises from any unauthorized access to the Platform through any User’s credentials, other than where any compromise of such credentials was caused by Lendscape’s breach of security.
18.6. The Customer acknowledges and agrees that the Platform is hosted by a third-party cloud service provider and that outages, interruptions, delays, loss of data, or security breaches are inherent in the use of cloud-hosted platforms. The Customer confirms that it has independently assessed and accepted these risks in selecting the Platform and the associated hosting arrangements, and except to the extent caused by Lendscape’s wilful breach of this Agreement, Lendscape shall not be liable for any loss, damage, cost, or expense suffered or incurred by the Customer arising from or in connection with any outage, interruption, delay, loss of data, or security breach attributable to the acts or omissions of the cloud hosting provider or to circumstances generally outside of Lendscape’s reasonable control.
18.7. Except as expressly set out in this Agreement, all warranties, representations, conditions and all other terms of any kind whatsoever implied by statute or common law are, to the fullest extent permitted by Applicable Law, excluded from this Agreement.
18.8. All claims under this Agreement must be brought and issued within 24 months after the date on which the first event or circumstance giving rise to the liability took place or began, or if longer, within the period prescribed by the applicable statute of limitations under the laws of the State of Florida.
19. Insurance
During the term of this Agreement Lendscape shall maintain in force insurance policies to cover its potential liability under this Agreement.
20. Force Majeure
20.1. Neither party shall be in breach of this Agreement or liable for any delays or failures to perform any of its obligations under this Agreement to the extent they are caused by a Force Majeure Event, provided it uses its reasonable endeavors to continue to perform where practicable using a reasonable alternative method. If the period of delay or non-performance continues for 60 (sixty) days, the Party whose obligations are not affected by the Force Majeure Event may terminate this Agreement by giving 30 days’ written notice to the other Party.
20.2. The occurrence of a Force Majeure Event shall not relieve the Customer of its obligation to pay the Charges in respect of the Services actually provided.
21. Disputes
21.1. If any dispute arises between the Parties with respect to this Agreement, the Parties shall first deal with them under the Escalation Procedure. If no settlement results from the meeting specified in the Escalation Procedure, either Party may commence legal proceedings, or the Parties may mutually agree to pursue an alternative dispute resolution procedure.
21.2. Nothing in this Agreement shall prevent either Party applying to a court for interim or emergency relief.
22. Non-solicitation
22.1. During the Term and for a period of 12 months thereafter neither Party shall (and shall procure that its Affiliates shall not) actively recruit directly or indirectly any employee of the other Party or its Affiliates, if that employee was known to or introduced to the recruiting party through the relationship under this Agreement, provided that this clause shall not apply to employees who have left their employment for a period of more than 6 months or who respond to a general advertisement placed by the recruiting party in the media.
23. Notices
Any contractual notice referred to in this Agreement must be sent by email to the relevant email address of the other Party as set out in the Order Form, with a copy sent by post to the business office of the other Party. Such contractual notice shall be deemed to have been received at the time of email transmission, or, if this time falls outside 9.00am to 5.00pm Monday to Friday or on a day that is a public holiday in the place of receipt, when business hours resume on the next Working Day.
24. Entire agreement
24.1. This Agreement sets out the entire terms agreed between the Parties relating to this engagement, and save where this Agreement expressly provides or where it refers to another document, it supersedes all other representations, warranties, terms and/or agreements (including, without limitation, any purchase order or other unilateral document), whether in writing or not, made between the Parties. For clarity, these Online Documents are incorporated by reference and form part of the Agreement as if set out in the Order Form in full. No other website terms (including click-through terms) apply.
24.2. Each Party acknowledges that in entering into this Agreement it does not rely on, and shall have no remedies in respect of, any statement, representation, assurance or warranty (whether made innocently or negligently) that is not set out in this Agreement.
24.3. Each Party agrees that it shall have no claim for innocent or negligent misrepresentation or negligent misstatement based on any statement in this Agreement. Nothing in this clause 24 shall limit or exclude any liability for fraudulent misrepresentation.
25. Customer Group
25.1. Lendscape acknowledges that the Customer may be entering into this Agreement for the benefit of itself and the Customer Group. Accordingly, if the Platform is used for the benefit of the Customer Group, Lendscape shall provide the Platform and Services in accordance with the following provisions of this clause 25.
25.2. Lendscape shall provide the Platform and Services to the Customer, and the Customer may use the Platform and Services itself and for the benefit of the Customer Group, and may make available the Platform for direct use by the Customer Group.
25.3. As directed by the Customer, Lendscape shall liaise with members of the Customer Group in respect of the Platform and Services for which they receive the benefit, and save where expressly noted in this Agreement, the Customer may perform any of its obligations (other than the obligation to pay the Charges) through any member of the Customer Group, in each case provided that any act or omission of a member of the Customer Group shall be treated as an act or omission of the Customer under this Agreement. The Customer shall be responsible for compliance by the Customer Group with this Agreement.
25.4. Where a member of the Customer Group is put under any obligation or made subject to any duty in this Agreement, the Customer shall procure that such member of the Customer Group will perform that obligation or carry out that duty.
25.5. The Customer may itself, on behalf of the members of the Customer Group, enforce any term of this Agreement which is expressly or impliedly intended to benefit the Customer Group, and the Customer shall be entitled to recover losses on behalf of the Customer Group as if the relevant losses had been suffered by the Customer itself under this Agreement, subject to the exclusions and limitations set out in this Agreement which shall apply in the aggregate to any losses suffered by the Customer Group.
25.6. No member of the Customer Group shall have a right to enforce any term of this Agreement directly against Lendscape. Lendscape shall not enforce any term of this Agreement directly against any member of the Customer Group, other than the Customer.
26. Assignment
26.1. Neither Party may assign or otherwise transfer their rights under this Agreement without the prior written consent of the other Party, such consent not to be unreasonably withheld or delayed.
26.2. The Customer agrees that Lendscape may subcontract any of its rights and obligations under this Agreement pursuant to the controls set out in Paragraph 4 of Schedule 6 (in respect of Sub-processors) and Paragraph 9 of Schedule 5 (in respect of sub-contractors generally).
27. Publicity
27.1. The Parties shall seek to agree, acting reasonably, the issue of a press release, shortly after the Effective Date, and agree to cooperate to draft further appropriate press releases and other public announcements relating to the subject matter of this Agreement and the relationship between the Parties. Where agreed with the Customer, Lendscape may use the Customer’s logo and reference the Customer as a client of Lendscape.
28. Miscellaneous terms
28.1. The Parties are independent parties and are not partners or principal and agent and this Agreement does not establish any joint venture, trust, fiduciary, agency or other relationship between them, other than the contractual relationship expressly provided for in it.
28.2. Nothing contained in this Agreement prevents Lendscape from providing services similar to the Services to any other person.
28.3. This Agreement is for the sole benefit of the parties and their respective permitted successors and assigns, and nothing in this Agreement, express or implied, confers any legal or equitable right, benefit, or remedy of any nature whatsoever upon any other person or entity.
28.4. If any part of this Agreement is deemed to be unenforceable or invalid, it shall be deemed to be modified to the minimum extent necessary to make it enforceable or valid, and shall not affect any other part of this Agreement.
28.5. Any failure or delay by either Party in exercising any right, power or privilege hereunder shall not operate as a waiver, nor shall any single or partial exercise of any right, power or privilege preclude any other or further exercise of it, or the exercise of any other right, power or privilege.
29. Counterparts
29.1. This Agreement may be executed in any number of counterparts and together all such counterparts shall constitute one and the same document.
29.2. Each Party agrees that this Agreement may be executed by electronic signature (for example DocuSign, Adobe Sign) and that such electronic signature is conclusive of a Party’s intention to be bound by this Agreement. The Parties waive any rights they may have to object to such treatment.
30. Governing law and jurisdiction
30.1. This Agreement and any dispute or claim arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of the State of Florida, without regard to conflict-of-laws principles.
30.2. The Parties irrevocably agree that the state courts located in Polk County, Florida or the U.S. District Court for the Middle District of Florida shall have exclusive jurisdiction to settle any dispute or claim that arises out of or in connection with this Agreement or its subject matter or formation (including non-contractual disputes or claims).
This Managed Service Schedule sets out the specification and details for the Platform and Managed Services, and forms part of, and is subject to the terms of, this Agreement.
1. Platform
1.1. The following table provides an overview of the Platform.
Lendscape Platform
| Service | Description and any applicable conditions |
|---|---|
| Platform | The specific Platform and Modules subscribed to by the Customer are set out in the applicable Order Form. |
| Technical Environment | Lendscape will manage the technical environment for the Platform (including servers, storage, technical components and operating systems required to host the number of production instances of the Platform and any non-production instances set out in the Order Form). |
| Hosting | Hosting of the Platform and Customer Data will be provided in an approved Hosting Location set out in the Order Form. |
| Data Storage | Data Storage for the Customer Data. Limited to 7 years historic Customer Data, unless otherwise stated in the Order Form. Fair use thresholds for the storage of Customer Data are outlined in the Order Form. If these are exceeded additional charges will apply. |
| Online Services Website | 1 x dedicated Client Web Portal URL for the production environment. 1 x dedicated Client Web Portal URL for one other non-production environment. All environments will require an SSL Certificate. Use to be in accordance with the Customer Security Controls and Fair Use Policy from time to time in force. |
| Secure Connectivity Presentation | A presentation at the perimeter of the Hosting Location to allow secure connectivity to and usage of the Platform by the Customer Group. Connectivity will be secured in accordance with the Customer Security Controls and Fair Use Policy. Customer Group presentation and connection is the responsibility of the Customer. |
2. In-scope Managed Services
The following table provides a detailed list of the individual Managed Services that Lendscape will provide in respect of the Platform. For each service, the table indicates whether or not a Managed Service is included or excluded in the Subscription Fee, in respect to production and non-production environment(s).
Operations
| Service | Description | Production | Non- Production |
|---|---|---|---|
| EOD / EOM Processing | Manage End-of-Day (EOD) and End-of-Month (EOM) batch-processing. See also Scheduled Downtime, in Schedule 2. | Included | Excluded |
| Data Backups | Perform a daily backup of Customer Data. Manage backup lifecycles, retention and secure destruction. | Included | Excluded |
| Data Archival | Save where clause 17.2 of the Platform Terms applies, Archival of a monthly Customer Data position for 7 yrs. Secure destruction of expired Customer Data after 7 yrs. Management of off-site/secondary storage where required. | Included | Excluded |
| Monitoring | Monitoring of Technical Environment and Platform for stability and incidents. Monitoring of EOD/EOM batch processing. Monitoring of any Platform interfaces (including web interfaces) notified to Lendscape and agreed by Lendscape to be included in the Services. Monitoring of Lendscape’s data communications connection with the Customer. | Included | Excluded |
| Alerting | Alerting via e-mail to the Customer for EOD/EOM batch processing progress, Incidents and warnings, Maintenance notices, and Escalation for priority incidents. | Included | Excluded |
| Data Communications | Management and monitoring of Lendscape’s data communications connections with the Customer. Management and monitoring of the technical environment’s external data communications connections (Internet access). | Included | Excluded |
| Failover Testing | Performance of failover testing for the production environment every 12 months, followed by a summary testing report for the Customer. | Included | Excluded |
| Minor Application Updates | Implementation of Updates to the current Release. | Included | Included |
| Third Party Software | Installing or managing any Customer third party software. | Excluded | Excluded |
Help Desk And Support Processes
| Service | Description | Production | Non- Production |
|---|---|---|---|
| Incident Management | Management and resolution of incidents in accordance with Schedule 3. Lendscape will access and implement resolutions into the Platform in accordance with the Incident Management Process. | Included | Excluded |
| Change Management | Management of Changes. | Excluded | Excluded |
Maintenance
| Service | Description | Production | Non-Production |
|---|---|---|---|
| Updates and Patching | Regular Updates of the Platform and technical environment. Implement emergency Updates in case of threat or security incident. | Included | Included |
| Security & Threat Management | Manage physical and logical separation of environments, servers and network traffic where required. Manage perimeter security. Manage anti-virus and anti-malware implementations in the technical environment. | Included | Included |
| Standard License and Certificate Management | Manage all Lendscape standard third-party licensing and certificates required for the technical environment. | Included | Included |
| Customer Specific License and Certificate Management | Manage any Customer specific third-party licensing and certificates required for the technical environment | Excluded | Excluded |
3. Additional Environments
3.1. Additional environments for non-production use (in addition to any non-production environments provided as listed in the Order Form) may be made available by Lendscape for an additional fee, provided that they will not be used in a production use and will be operated separately to, and segregated from, the production environment.
3.2. Operation and management of such additional environments will be documented and charged under a SOW.
4. Customer Data
4.1. The Customer shall have sole responsibility for:
4.1.1. the legality, reliability, integrity, accuracy and quality of the Customer Data;
4.1.2. the preparation and input of the Customer Data into the Platform and for the scheduling and control of the processing of all such Customer Data; and
4.1.3. taking backups of all Customer Data which is not in the Platform at such times and over such periods as are chosen exclusively by the Customer.
4.2. The Customer acknowledges and accepts that Lendscape shall not be responsible for any fault or error in the preparation or input of the Customer Data or for its subsequent processing by any Users, or for any loss, destruction, alteration or disclosure of Customer Data caused by any third party (except those third parties sub-contracted by Lendscape to perform the Services).
4.3. The Customer undertakes to ensure that the Customer Data will not contain any Virus or anything illegal and that it shall not store, distribute or transmit any Virus, or any material through the Platform that is unlawful or harmful.
4.4. In the event of any loss or damage to Customer Data, the Customer’s sole and exclusive remedy shall be for Lendscape to use reasonable endeavors to restore the lost or damaged Customer Data from the latest back-up of such Customer Data maintained by Lendscape in accordance with the backup procedure described in the table above.
5. Acceptable Use
5.1. The Customer shall, and shall ensure that the Users shall, comply at all times with the Customer Security Controls and Fair Use Policy in their use of the Platform. The Customer shall notify Lendscape promptly if it becomes aware of any breach of the Customer Security Controls and Fair Use Policy.
5.2. Lendscape may include functionality within the Platform to automatically send Usage Data to Lendscape for the purpose of verifying the Customer’s use of the Platform (including to calculate the Charges). The Customer shall not intentionally do anything to disable, impair or tamper with such functionality, or the data received by Lendscape.
5.3. Customer must ensure that it does not engage in (a) excessive or abusive use of the Platform beyond the scope or thresholds as defined in this Agreement, or (b) any automated or systematic extraction of data resulting in a download in excess of 20% of the overall reporting volume in any 24 hour period.
5.4. Lendscape reserves the right to review and make reasonable modifications to the Customer Security Controls and Fair Use Policy, with prior notice to the Customer. Any such changes shall be effective immediately upon communication from Lendscape to the Customer or notifying the Customer through other means.
6. Monitoring and suspension
6.1. Lendscape reserves the right to monitor and evaluate the use of the Platform to ensure compliance with this Agreement, as further set out in the Customer Security Controls and Fair Use Policy.
6.2. In the event that Lendscape determines, at its sole discretion, that the Customer has not complied with the Customer Security Controls and Fair Use Policy, Lendscape may issue a warning to the Customer, including the necessary requirements for mandatory compliance with the Customer Security Controls and Fair Use Policy. If the Customer fails to meet the requirements set out in the warning, Lendscape may take appropriate actions, including but not limited to:
6.2.1. suspending or limiting access to the Platform; and
6.2.2. pursuing legal remedies as necessary.
7. Training
7.1. On the Customer’s reasonable written request, with reasonable pre-agreed costs to be paid by the Customer, Lendscape agrees to provide training on the Platform to the Customer.
7.2. The Parties (acting reasonably) shall agree the content, frequency, duration, timing and delivery method of the training, which shall be documented in a SOW agreed by the Parties.
8. Development Roadmap
8.1. Customer acknowledges that the Platform is a “one to many” product with configurable functionality, and that Lendscape may make Releases to the Platform and its functionality in accordance with its product development roadmap, or may migrate the Platform to replacement environments. These are made available generally to all customers.
9. Releases
9.1. The Customer agrees to implement and roll out at least one new Release in each 24-month period (or such other frequency as agreed in the Order Form) during the term of this Agreement. If the Customer does not take a Release from Lendscape at any time during such period Lendscape may:
9.1.1. require the Customer to take the then current Release and put it into live operation within six months of it being requested by Lendscape; and
9.1.2. increase the Subscription Fee pursuant to the charging terms in the Order Form.
9.2. Lendscape may implement Updates at any time in order to fix bugs or issues, or workarounds to any incidents, in accordance with the Incident Management Process.
9.3. The development and implementation of any Updates or Releases or other updates, patches or migrations to the Platform shall not be deemed to be subject to the Change Control Procedure.
10. Acceptance
10.1. This Paragraph applies where any Deliverable is to be Accepted by the Customer (which shall be undertaken by the Customer on its own behalf and on behalf of the Customer Group).
10.2. The Customer will perform the agreed acceptance tests (“Acceptance Tests”) in relation to a Deliverable, with the cooperation of Lendscape, against the acceptance criteria set out in or otherwise agreed pursuant to the relevant SOW (the “Acceptance Criteria”). The Acceptance Tests and Acceptance Criteria shall in each case be such as are reasonably required to show that the Deliverable complies with the technical specification(s) set out in the SOW.
10.3. The Customer shall notify Lendscape of the date when the Customer will commence the Acceptance Tests, and such Deliverable shall have passed Acceptance (and be “Accepted”) if:
10.3.1. the Customer notifies Lendscape in writing that the Deliverable meets the Acceptance Criteria;
10.3.2. the Customer fails to (i) commence the Acceptance Tests within fifteen Working Days of the Deliverable being made available by Lendscape for testing, or (ii) notify Lendscape of any failure to meet the Acceptance Criteria within fifteen Working Days of commencing the Acceptance Tests; or
10.3.3. the Customer Group puts the Deliverable or any part of it into production use.
10.4. The Customer shall not withhold its Acceptance if Lendscape can reasonably demonstrate that the Deliverable meets the Acceptance Criteria, or where the Customer cannot reasonably identify any failure.
10.5. Where the Customer claims that the Acceptance Tests have been failed:
10.5.1. the Customer shall cooperate with Lendscape in identifying how the Deliverable failed to meet the Acceptance Criteria;
10.5.2. the Parties shall agree the method of remedying the defects detected (including the time scales), and Lendscape shall update the Deliverable for re-testing;
10.5.3. the Customer shall repeat the Acceptance Tests under this Paragraph 10 in respect of those parts of the updated Deliverable; and
10.5.4. if the Parties dispute whether or not a Deliverable meets the Acceptance Criteria, such dispute shall be resolved through the Escalation Procedure.
10.6. If Lendscape is unable to remedy any material failure of the Deliverable to conform with the Acceptance Criteria within three cycles of the Acceptance Tests, then the Customer shall be entitled either: (i) to reject the Deliverable without further liability to Lendscape; or (ii) to accept the Deliverable subject to a change of Acceptance Criteria or amendment of the technical specification (in such case the Parties will, acting reasonably, agree a reduction in the Charges in respect of the Deliverable if this is reasonable, taking into account all the relevant circumstances).
10.7. If a new Release fails the Acceptance Tests on three cycles, the Customer may reject that Release and the Customer shall revert to the previous Release in use by the Customer.
10.8. Once a Deliverable has been Accepted, in the case of failure of any subsequent Deliverables to meet the Acceptance Criteria in any subsequent Acceptance Tests, the Customer shall have the rights set out above in relation to such failure, but shall not be entitled to reject Deliverables which have already been Accepted.
10.9. Once a Deliverable has been Accepted it shall be put into production use and may not subsequently be rejected. Any subsequent issues shall be reported and resolved through the Support Services under Schedule 3.
This Service Level Agreement forms part of, and is subject to the terms of, this Agreement.
1. General
1.1. This Service Level Agreement applies only in respect of the production instance of the Platform, and references to the Platform do not include any non-production instances.
1.2. Unless otherwise stated in the Order Form, the applicable time zone shall be EST/EDT on a Working Day.
2. Scheduled Downtime
2.1. The Customer accepts that the Platform may not be available during routine maintenance as set out in this Paragraph (“Scheduled Downtime”).
2.2. For the execution of regular maintenance and for normal processing at the end of day (EOD) and end of month (EOM), the Platform will be unavailable for use between 10:00 PM and 04:00 AM (EST/EDT) to allow for safe completion of the processing and for the implementation of Updates.
2.3. Lendscape shall be entitled (with as much prior notice to the Customer as is reasonably in the circumstance) to suspend access to the Platform for maintenance purposes at any time on a Sunday or public holiday.
2.4. Otherwise, all necessary maintenance downtime will be scheduled in advance by mutual agreement with the Customer, such agreement not to be unreasonably withheld or delayed.
3. Emergency Downtime
3.1. Lendscape shall be entitled to suspend access to the platform in an emergency situation determined by Lendscape acting reasonably in light of factors and circumstances concerning the integrity or security of the Platform (“Emergency Downtime”). An emergency event shall include:
3.1.1. if non-approved traffic, or traffic from an unknown or questionable source, that matches known patterns of malicious activities, threats or anomalies, is detected by Lendscape and found to be impacting the stability or security of the Platform;
3.1.2. taking the Platform or any interface or infrastructure off-line in a failover event, where there is material disruption at the third-party hosting provider or facility, or to prevent or mitigate a cyber-attack (in progress or anticipated); or
3.1.3. where Lendscape is made aware of any material vulnerability in any third-party software or infrastructure.
3.2. Lendscape will promptly notify the Customer of the reasons for any Emergency Downtime and access to the Platform will be resumed once the active threat ends or is mitigated.
3.3. If the source of any emergency event is under the control of the Customer Group (such as where malicious traffic is within the scope of the Customer’s control), the Customer shall remedy the root cause as soon as possible.
4. Failover RTO and RPO
4.1. The production version of the Platform will be operated with a disaster recovery facility as set out in the Order Form, to provide a failover to an alternative location in the event of a local Disaster, exceeding typical disaster recovery provisions. A “Disaster” means a catastrophic loss of or inability to access the Platform for such a period that normal provision of the Platform is not possible without a switch over to an alternative location.
4.2. If a local Disaster occurs within the production version of the Platform, Lendscape will provide the Customer with access to the Platform at an alternative location within the target Recovery Time Objective (the maximum targeted period that it will take to return to service in the event of a Disaster) as set out in the Order Form, and to a target Recovery Point Objective (the point from which data will be recovered in the event of a Disaster) as set out in the Order Form.
4.3. Non-production versions of the Platform are excluded from this provision, unless specifically implemented as a Project under SOW.
5. Availability Service Level
5.1. Lendscape agrees to ensure that the production version of the Platform will be Available to the Customer 99.5% of all time in any month, on a 24 hours and 7 days a week basis excluding (i) Scheduled Downtime, Emergency Downtime (each as defined in Paragraphs 2 and 3 of this Schedule 2, above, respectively); (ii) any unavailability attributed to a Force Majeure Event or Customer’s breach of this Agreement, (iii) under clause 2.4.3.2 of the Platform Terms, or (iv) time awaiting a response from the Customer once Lendscape has made request for assistance related to an Incident (the “Availability SLA”).
5.2. For the purpose of the Availability SLA, “Available” means that the Platform is available for access by Users.
6. Service Credits
6.1. If during any month Lendscape does not meet the Availability SLA, then for each whole percentage point by which availability falls below 99.5% in that month, the Customer may submit a written claim to Lendscape for a Service Credit equal to 1% of the Monthly Fee, provided that the total Service Credits payable in respect of any month shall not exceed 5% of the Monthly Fee. For the purposes of this Paragraph, “Monthly Fee” means one-twelfth (1/12) of the annual Subscription Fee.
6.2. Any Service Credits are the Customer’s sole and exclusive remedy for any failure by Lendscape to meet the Availability SLA.
This Support Schedule forms part of, and is subject to the terms of, this Agreement.
1. General
1.1. This Schedule sets out the Incident Management Process for resolving Incidents and the provision of support to the Customer Group in respect of the production instance of the Platform, as included in the Subscription Fee. Any request for support outside the scope of these Support Services will be agreed between the Parties and may be subject to additional Charges and may need to be documented as a Change or Statement of Work for a new Project.
1.2. The Customer will ensure that it employs at all times and on a full-time basis at least one User who has received formal training from Lendscape in the use of the Platform and in the correct use of the call logging procedure (“Trained User”). The Trained User will handle the first line of support and seek to provide answers to problems and queries to the Users.
1.3. The following definitions apply to this Support Schedule:
1.3.1. Notification means when Lendscape receives a valid and complete Ticket (in accordance with paragraph 2.2 below).
1.3.2. Priority means the urgency of an Incident, being either Critical, Urgent, High, Medium or Low (each as defined in the Paragraph 3 below).
1.3.3. Resolution means, in respect of an Incident, the restoration of the User’s ability to access and use the Platform (or relevant part thereof) in accordance with the Documentation.
1.3.4. Resolution Time means the target time in which Resolution is to be achieved, as set out in the table at Paragraph 4 below.
1.3.5. Ticket means a request for Support Services for an Incident.
1.3.6. Workaround means a solution to an Incident that mitigates the impact without addressing the root cause.
1.4. Unless otherwise stated in the Order Form, the applicable time zone shall be EST/EDT on a Working Day.
2. Notification
2.1. A User may notify Lendscape of any Incident by raising a Ticket in accordance with this Paragraph 2.
2.2. Notification of a Ticket is deemed to occur when Lendscape receives from a User all the following information in writing via the completion of a web form approved in advance by Lendscape for this purpose:
2.2.1. a clear description of and full details of the Incident notified by the Ticket;
2.2.2. the User’s reasonable assessment of the Priority for the Ticket;
2.2.3. if relevant, identification of the exact environment (production or otherwise) to which the Ticket relates;
2.2.4. any internal reference number applied to the Ticket by the Customer Group’s internal procedures; and
2.2.5. all relevant supporting documentation and information concerning the Incident notified by the Ticket,
2.2.6. and Lendscape shall not be obliged to commence work on the Ticket until such information has been provided.
2.3. Lendscape may close or assign the Ticket to another process if in Lendscape’s reasonable opinion, it determines and notifies the User that the Ticket is not covered by the scope of the Support Services (such as it falls under Paragraph 4.4 below, or relates to a request for a Change or an Enhancement). Invalid Tickets shall be referred back to a Trained User requesting further information and / or the Parties may agree to convert the Ticket into a request for a Change or Enhancement.
2.4. For valid support Tickets, Lendscape will, within 2 Business Hours of Notification, confirm the Priority of the Ticket, which may at Lendscape’s reasonable discretion be different to the original Priority proposed by the User.
2.5. The Customer shall provide (and as necessary procure from Users and members of the Customer Group) such cooperation, relevant information, documentation and expertise as Lendscape may reasonably require to handle a Ticket and implement a Resolution, and shall procure any relevant third party retained by Customer Group cooperate with Lendscape as reasonably required. Lendscape reserves the right to suspend work on a Ticket (and such time shall not count towards the Resolution Time), if at any time there are delays in providing such cooperation, information, documentation or expertise.
3. Priorities
3.1. The description of each type of Priority relating to an Incident in the production environment is as follows:
3.1.1. Critical means that the whole or a significant part of the production instance of the Platform is unavailable or is not usable to such an extent that it prevents the Customer Group from carrying on its business;
3.1.2. Urgent means that a major part of the production instance of the Platform is materially restricted in its use or is in some other way unavailable, and requires timely resolution to ensure the remainder of the Platform can still be used;
3.1.3. High means that a major part of the production instance of the Platform is materially restricted in its use or is in some other way unavailable, while the remainder of the Platform can still be used;
3.1.4. Medium means that a minor part of the production instance of the Platform is materially restricted in its use or is in some other way unavailable, while the remainder of the Platform can still be used; and
3.1.5. Low means a minor feature of the production instance of the Platform is not operating as expected resulting in minimal adverse impact to the Customer Group’s business or any other Incident affecting the Platform that is not a Critical, Urgent, High or Medium Priority Incident.
4. Ticket Resolution – targets
4.1. Only Business Hours shall be counted when calculating any timescales in this Support Schedule. For example, a Notification made at 6:30 PM on any day of the week will not start to have any effect until 9:00 AM on the next Working Day, and the period of two Business Hours for Lendscape to respond to a Notification given at 4:30 PM on any Working Day can be responded to by Lendscape at any time up to 10:00 AM on the next Working Day.
4.2. Subject to the Customer complying fully with its obligations under this Support Schedule, Lendscape shall use reasonable endeavours to effect Resolution within the following Resolution Times from Notification:
| Critical | Urgent | High | Medium | Low |
|---|---|---|---|---|
| 7.5 Business Hours | 5 Working Days | 14 Working Days | In the Customer’s next Release which is not less than 30 days from the date of Notification | In a future Release or as scheduling permits |
4.3. Lendscape reserves the right to change the allocation or process of any Ticket at any time, where it is appropriate to do so, and to notify the relevant User accordingly.
4.4. If Lendscape’s investigation indicates that the issue to which the Ticket relates is caused to any extent by the following, such issues may be excluded from the support provided by Lendscape:
4.4.1. the Customer’s own systems or environment, or the Customer Data;
4.4.2. third-party software or services;
4.4.3. Customer’s breach of this Agreement or misuse of the Platform contrary to the Documentation; or
4.4.4. unauthorized modifications to the Platform.
4.5. In such cases, Lendscape may either decline to fulfil that Ticket, or fulfil that Ticket subject to agreeing a Change or Statement of Work. Once Resolution confirmation has occurred Lendscape will close the Ticket by noting its closure on Lendscape’s system. Lendscape will inform the Customer of all Tickets that are closed.
4.6. Lendscape may close a Ticket if the Customer, when requested by Lendscape, fails to comply with its obligations under this Support Schedule for a period of more than 10 Business Days.
5. Incident Management Support Process
5.1. The Incident Management Process will seek to restore normal service operation as quickly as possible, and minimize the adverse impact on business operations, by resolving the service interruption. Where possible the Resolution will be effected by an Update for a permanent correction of the underlying root cause. If this is not possible, Resolution will be effected by means of a Workaround.
5.2. Where Lendscape effects a Resolution by means of a Workaround, Lendscape reserves the right to effect Resolution of any future Incidents caused by the same known error using the same Workaround before any underlying root cause is itself rectified.
5.3. Following provision of a Resolution by means of a Workaround, Lendscape will investigate the underlying cause(s) of the Incident and if necessary, generate a Resolution in the form of an Update.
5.4. The Customer shall after a Resolution has been provided by Lendscape, test any Resolution with all reasonable care and skill and shall confirm acceptance to Lendscape as soon as reasonably practicable but in any event, within 15 Working Days.
5.5. A failure to revert within the time stipulated above shall be deemed to be confirmation that the Incident has been resolved and the Ticket may be closed by Lendscape.
This Governance Schedule forms part of, and is subject to the terms of, this Agreement.
1. Representatives
1.1. Each Party shall appoint a representative (“Lendscape Representative” and “Customer Representative”, respectively, and together referred to as the “Representative(s)” of the Parties) to manage and oversee this Agreement. The Representatives shall be the persons listed in the Order Form or as otherwise notified by the relevant Party to the other from time to time.
1.2. The Representatives will cooperate in good faith to support the delivery and operation of the Services and to address any issues arising under this Agreement.
2. Progress Meetings
2.1. The Parties shall meet regularly to review progress, performance, and any relevant matters arising under this Agreement. Meetings may be conducted in person or remotely, and the frequency shall be agreed between the Parties from time to time.
3. Escalation Procedure
3.1. The Representatives shall seek to resolve issues acting reasonably and in good faith at the appropriate operational level.
3.2. If unresolved informally, the matter shall be escalated through the agreed contact hierarchy, as specified in the table below or otherwise agreed between the Parties, before any formal actions are taken.
| Escalation Steps | Customer | Lendscape | Timescale |
|---|---|---|---|
| First level escalation | Customer Project Manager | Lendscape Project Manager | 5 Working Days to resolve. If not resolved within this timeframe, escalate to next level |
| Second Level escalation | Customer Relationship Manager | Lendscape Relationship Manager | 5 Working Days to resolve. If not resolved within the timeframe, escalate to the next level. |
| Third level escalation | Appropriate member of Senior Leadership Team | Appropriate member of Senior Leadership Team | 10 Working Days to resolve |
4. Change Control Procedure
4.1. Changes will be carried out in accordance with the Change Control Procedure in this Schedule 4 and once a Change has been agreed it will be binding on Lendscape and the Customer.
4.1.1. Changes to the Services shall be agreed through a written Statement of Work or similar written agreement, signed by both Parties.
4.1.2. Emergency or urgent Changes may be initiated by agreement in writing, with formal documentation to follow promptly.
4.1.3. Neither Party shall unreasonably withhold agreement to a proposed change.
4.2. No member of the Customer Group other than the Customer has the right to request or the authority to agree any Change and all changes must be agreed as between Lendscape and the Customer only.
5. Policies
5.1. Lendscape, the Customer and the Customer Group shall comply with the terms of the following policies as available in the Lendscape Trust Centre:
5.1.1. Customer Security Controls and Fair Use Policy
5.1.2. Escrow Policy
5.1.3. Releases Policy
5.2. Lendscape reserves the right to amend any of these policies at any time, or to introduce a new policy dealing with any other matter, provided that any such amendment or new policy does not materially impact the Customer’s rights or obligations under this Agreement.
5.3. Lendscape will notify the Customer following any such change (such notification to be effected by bringing such amendments or new policies to the attention of the Customer Representative or by making them available in Lendscape’s Trust Centre).
This Regulatory Schedule incorporates certain additional rights and obligations into this Agreement intended by the parties to support the Customer’s compliance with Applicable Financial Services Laws and supervisory expectations concerning third-party relationships, and forms part of, and is subject to the terms of, this Agreement.
1. Definitions
1.1. The following definitions and interpretation apply in this Regulatory Addendum. Capitalized terms used but not defined below have the meanings ascribed to them elsewhere in this Agreement.
1.2. Applicable Financial Services Law means to the extent applicable, the U.S. federal and state statutes, regulations, supervisory guidance, and binding orders governing regulated financial services and the use of third‑party service providers, as amended from time to time, including without limitation: (i) the Interagency Guidance on Third‑Party Relationships: Risk Management (88 Fed. Reg. 37,920, June 9, 2023), and any successor issuances; (ii) the Interagency Guidelines Establishing Standards for Safety and Soundness and the Interagency Guidelines Establishing Information Security Standards (12 CFR part 30, Appendices A and B (OCC); 12 CFR part 208, Appendices D‑1 and D‑2 (Board); 12 CFR part 364, Appendices A and B (FDIC)); (iii) the FFIEC IT Examination Handbook and related guidance (including, without limitation, Information Security, Outsourcing Technology Services, Business Continuity Management, and Cloud Computing); (iv) the Gramm‑Leach‑Bliley Act (15 U.S.C. §§ 6801–6809) and implementing regulations, including the FTC Safeguards Rule (16 CFR part 314); (v) the computer‑security incident notification requirements for banking organizations and their service providers (including 12 CFR part 53 (OCC); 12 CFR part 225, subpart N (Board); and 12 CFR part 304, subpart C (FDIC)); (vi) applicable state financial‑services laws, including cybersecurity, data protection, and third‑party risk management requirements; and (vii) any applicable rules, guidance, directives, consent orders, supervisory agreements, or other binding requirements issued by any Competent Authority with supervisory or examination authority over Customer.
1.3. Audit means any access, inspection or audit of Lendscape under Paragraph 10.2 below.
1.4. Competent Authority means any governmental body, or regulatory or supervisory body or authority (including any resolution authority), having authority to enforce the requirements of Applicable Financial Services Law in respect of the Customer or all or any part of the Services.
1.5. ICT Services means digital and data services provided through information and communication technology systems on an ongoing basis, and in respect of which the Customer is required to ensure that there are certain requirements and controls under Applicable Financial Services Laws.
1.6. Minimum Security Requirements means the minimum technical and organizational security measures as set out in the Customer Security Controls and Fair Use Policy.
1.7. Regulated Entity means an entity that is subject to the application of Applicable Financial Services Law.
1.8. Regulated Service Recipient means any member of the Customer Group that (i) is a Regulated Entity and (ii) receives or benefits (directly, or indirectly through the Customer) from the provision of the Services under this Agreement.
1.9. Technical Standards means the implementation and regulatory technical standards issued under Applicable Financial Services Law, and any additional mandatory requirements or standards issued by a Competent Authority.
1.10. Nothing in this Regulatory Addendum shall be interpreted as limiting or curtailing any rights of a Competent Authority to exercise their legal powers.
2. Application
2.1. Lendscape accepts that the Customer shall be entitled to pass on the benefit of this Regulatory Addendum to any Regulated Service Recipient, provided that only the Customer may directly enforce this Regulatory Addendum against Lendscape.
3. Additional obligations and costs
3.1. Given the additional burden to Lendscape in complying with any rights that the Customer may have under this Regulatory Schedule, the Parties agree that the Customer shall exercise its rights under this Regulatory Addendum acting reasonably and in good faith to achieve what is necessary and appropriate to remain consistent with Applicable Financial Services Law, and shall, taking a proportionate, risk-based approach, accept alternative solutions made available by Lendscape (such as Lendscape’s own internal reports, third party certifications/reports, and pooled audits and testing) where they still enable the Customer to meet its obligations under Applicable Financial Services Law.
3.2. Any support provided by Lendscape in connection with the Customer’s exercise of its rights under this Regulatory Addendum will be charged to Customer at the Lendscape Hourly Rate. Where requested in writing by the Customer, Lendscape will provide the Customer with an estimate of any additional support.
4. Service information
4.1. The Order Form and Schedule 1 sets out a clear and complete description of the Services and all functions to be provided by Lendscape.
4.2. The Service Level descriptions are set out in Schedule 2. The Parties agree that, in the context of the services, Schedule 2 sets out appropriate performance targets within the agreed Service Levels to allow effective monitoring by the Customer of the Services and enable appropriate corrective actions to be taken, without undue delay, when agreed Service Levels are not met.
4.3. Lendscape shall report on its performance against the Service Levels on a periodic basis (and at such intervals and in such form as may be set out in Schedule 2).
4.4. Further details on Lendscape’s data and security practices are set out on the Lendscape website: Trust and Compliance.
5. Cooperation and reporting
5.1. Lendscape will reasonably cooperate with any Competent Authorities in connection with the Services, including by providing information and reasonable access to relevant records and investigation powers and personnel, to the extent required by Applicable Financial Services Law. If, and to the extent the Bank Service Company Act or similar authority applies, Lendscape acknowledged it may be subject to examination regarding the Services. Notwithstanding the foregoing, if a Competent Authority seeks to exercise its supervisory authority over a Regulated Service Recipient, the Customer shall use its reasonable endeavors to resolve the Competent Authority’s inquiries or requests without seeking access to or information from Lendscape (such as by providing any security documentation, reports, certificates, or through discussions with the Customer’s subject matter experts and reviewing controls and processes in place).
5.2. Where any assistance or cooperation under this Regulatory Addendum includes the provision of confidential information of Lendscape, the Customer shall treat it in accordance with the confidentiality obligations in this Agreement. Where such confidential information is provided to a Competent Authority, without prejudice to the Competent Authority’s legal rights, the Customer shall make the Competent Authority aware of the confidential nature of such information.
5.3. In addition to any reporting obligations set out in this Agreement, Lendscape shall promptly notify the Customer of any inquiry form a Competent Authority relating to the Services (unless legally prohibited), and of any circumstance arising that is likely, in Lendscape’s reasonable opinion, to have a material impact on Lendscape’s ability to carry out any function of the Services in compliance with this Agreement or applicable laws. In respect of any such material developments, Lendscape will provide any available and relevant reports, and/or a summary of such reports, reasonably requested by the Customer.
6. Service and data locations
6.1. Unless otherwise set out in this Agreement, Lendscape shall only provide the Services, including any sub-contracted services, and store and process the Customer Data, from the regions or countries set out in the Order Form.
6.2. Lendscape shall notify the Customer as soon as reasonably possible in advance if it envisages changing the agreed locations, and:
6.2.1. the Customer may raise reasonable objections by giving Lendscape notice in writing within thirty (30) days of being notified on the change, and the Customer and Lendscape shall seek to resolve any objections acting reasonably and in good faith; and
6.2.2. if Lendscape and the Customer are not able to resolve (acting reasonably and in good faith) any objection raised within thirty (30) days of the Customer raising the issue, the Customer may terminate this Agreement (or relevant Service) (subject to payment of the Early Termination Fee, and without prejudice to the exit arrangements in Paragraph 12 below) on thirty (30) days written notice to Lendscape.
7. Data and security
7.1. Lendscape shall implement the Minimum Security Requirements in respect of the Services to seek to ensure the availability, authenticity, integrity and confidentiality of Customer Data and other confidential, personal or otherwise sensitive information of the Customer.
7.2. Lendscape shall ensure that there are appropriate technical and operational measures to take effect on the termination of this Agreement or relevant part of the Services, or in the event of any circumstance that undermines the continuation of Lendscape’s business (such as any insolvency, resolution or discontinuation of the business operations of Lendscape), such that Lendscape shall return any Customer Data to the Customer in accordance with clause 17.2 of the Platform Terms.
7.3. As and when reasonably required by the Customer, Lendscape shall:
7.3.1. provide the Customer with reasonable assistance if the Customer suffers an ICT incident related to the Services; and
7.3.2. at the Customer’s reasonable cost (to be agreed in advance based on the Lendscape Hourly Rate), participate in any relevant and proportionate ICT security awareness programs and digital operational resilience training reasonably requested by the Customer (e.g. only where Lendscape cannot demonstrate that its staff have already undertaken equivalently robust training) and reasonably agreed and documented by the Parties at appropriate intervals.
7.4. The costs of any Lendscape assistance under Paragraph 7.3.1 above shall be borne:
7.4.1. by Lendscape, to the extent it relates to any breach by Lendscape of this Agreement; or
7.4.2. otherwise, by the Customer based on the pre-agreed Lendscape Hourly Rate.
7.5. Lendscape’s assistance or response to an ICT incident shall not be construed as an acknowledgement by Lendscape of any fault or liability with respect to the ICT incident.
8. Business continuity and testing
8.1. Lendscape shall:
8.1.1. perform the Services in such a manner as to reduce, so far as is practicable, the operational risk and risk of service disruption to the Customer and its customers; and
8.1.2. maintain written business continuity and disaster recovery plans aligned to industry standards and relevant FFIEC guidance, undertake reasonable testing of such arrangements on a periodic basis (not less than annually, including recovery time objectives relevant to the Services), and the results of such testing and any material remediation actions will be reported to the Customer where appropriate or on request.
8.2. At the Customer’s reasonable cost (to be agreed in advance based on the Lendscape Hourly Rate), and on reasonable advance notice:
8.2.1. where reasonably requested by the Customer (e.g. where Lendscape cannot demonstrate particular requirements have been met through its scheduled testing reports), the Customer may request to participate in the testing of Lendscape’s business contingency arrangements (in accordance with such reasonable and practicable scope as agreed between the Parties); and
8.2.2. where reasonably requested by the Customer (e.g. where the Customer is required to undertake such testing under Applicable Financial Services Law and Lendscape cannot demonstrate that it has recently undertaken equivalent testing meeting the applicable requirements), the Parties shall work together to agree pooled or other third party security and threat-led penetration testing to assess the effectiveness of any security, cyber and other ICT security measures and processes that have been implemented in respect of the Services (such as security and access protocols to systems and infrastructure).
8.3. Where any testing may have an adverse impact on Lendscape, its business operations, or its other clients, the Customer shall accept, in accordance with the scope and parameters set out in Applicable Financial Services Law, that such testing may be undertaken by a third party engaged by Lendscape for the benefit of several financial entities. Lendscape shall share the scope of such third-party testing to validate that it meets the relevant legal requirements.
8.4. If the findings of such testing lead to the conclusion that remediation activities should be implemented, Lendscape agrees to implement and complete effective remediation plans.
9. Subcontracting
9.1. The Customer provides its general authorization that Lendscape may engage sub-contractors (which may include Lendscape Affiliates) to perform all or any part of the Services. Lendscape remains responsible under this Agreement for services performed by its sub-contractors to the same extent as if Lendscape performed them itself.
9.2. When appointing any subcontractors, Lendscape shall:
9.2.1. carry out appropriate vendor due diligence over the subcontractor;
9.2.2. oversee those services that it has subcontracted to ensure that material terms of this Agreement are met; and
9.2.3. ensure that it requires such third party to comply with all laws and regulatory requirements that apply to the third party in its performance of the subcontracted services, and to provide Lendscape with information and assistance to ensure Lendscape can comply with this Agreement and this Regulatory Addendum.
9.3. Lendscape will keep Customer informed, upon request, of any sub-contractor engaged in the performance of any of Lendscape’s obligations under this Agreement (and which is available at Conveyor).
9.4. If Lendscape intends to replace a sub-contractor or materially change the arrangements in place with a sub-contractor engaged in critical or important functions of the Services:
9.4.1. Lendscape shall notify the Customer of such material change and shall make available any relevant information reasonably requested by the Customer (which Lendscape may redact to remove any non-relevant or commercially sensitive information) to enable the Customer to carry out its own risk assessment of the change;
9.4.2. the Customer may raise reasonable objections by giving Lendscape notice in writing within thirty (30) days of being notified on the change, and the Customer and Lendscape shall seek to resolve any objections acting reasonably and in good faith; and
9.4.3. if Lendscape and the Customer are not able to resolve (acting reasonably and in good faith) any objection raised within thirty (30) days of it being raised, then Lendscape or the Customer may terminate this Agreement or relevant Service (subject to payment of the Early Termination Fee, and without prejudice to the exit arrangements in Paragraph 12 below) on thirty (30) days written notice to the other Party.
9.5. Lendscape shall provide any further details on its sub-contractors (which Lendscape may redact to remove any non-relevant or commercially sensitive information) as reasonably requested by the Customer from time to time.
10. Monitoring and audit
10.1. The Customer shall have the right to monitor, on an ongoing basis, Lendscape’s performance under this Agreement, which shall primarily be undertaken through periodic service and relationship meetings as reasonably requested by the Customer to discuss performance against the Service Level Agreement and by Lendscape making external audit reports (or summaries thereof) available to the Customer on request (at Lendscape’s option, via the Lendscape Trust Centre for self-service by the Customer, or otherwise).
10.2. Where required by the Customer to meet its legal obligations, or where a Competent Authority exercises its rights of examination or access, Lendscape shall appropriate rights of access, inspection and audit to the Competent Authority or the Customer (or an appointed independent third party, subject to appropriate confidentiality restrictions), subject to multi-tenant and security safeguards.
10.3. Notwithstanding the rights of Audit above, the Parties shall seek to agree, acting reasonably, an alternative assurance process (such as pooled audits, if mutually agreed, or independent third-party certifications made available by Lendscape (at Lendscape’s option, via the Lendscape Trust Centre for self-service by the Customer, or otherwise)) if Lendscape’s business operations or its services (including the security, privacy, confidentiality or operational resilience of Lendscape), or the rights of other clients of Lendscape, could be adversely affected by an Audit proposed by the Customer.
10.4. In respect of any Audit:
10.4.1. the Customer shall limit any Audit to once per year, unless a more frequent Audit is required by a Competent Authority or applicable law;
10.4.2. the Customer shall exercise its right of Audit taking a proportionate and risk-based approach, in light of the information and internal and external reports and certificates Lendscape can make available to the Customer (including via the Lendscape Trust Centre for self-service by the Customer);
10.4.3. the Customer shall provide Lendscape with at least fourteen (14) days’ written notice of such Audit, unless this is not possible due to an emergency or crisis situation or would lead to a situation where the Audit would no longer be effective;
10.4.4. the Customer shall provide Lendscape in advance with details on the scope and frequency of the Audit, and the Parties shall agree the procedures to be followed for such Audits in line with commonly accepted audit standards;
10.4.5. Audits will be conducted in a manner that does not have any adverse impact on Lendscape’s normal business operations or other clients;
10.4.6. Lendscape may supervise all persons undertaking such Audit; and
10.4.7. Lendscape shall take reasonable steps to ensure that the effective exercise of any Audit is not impeded or limited by other contractual arrangements or implementation policies, and shall provide its cooperation during the Audit; and
10.4.8. Lendscape shall give all necessary assistance (subject to paragraph 10.3 above) to the conduct of any Audit during the Term, but will be able to charge the Customer for all time spent at its then current rate for professional services.
10.5. Subject to Paragraph 10.4.7 above:
10.5.1. if the Customer, or anyone acting on its behalf, is performing an audit in an environment where it could come into contact with confidential information, or data, information, or resources belonging to another client of Lendscape, or impact the security or continuity of services to other clients, the Customer and Lendscape shall work together to agree a working method which will reduce the risks arising from such contact and implement appropriate access and confidentiality measures to ensure that any risks to such environments are avoided or mitigated; and
10.5.2. the Customer agrees to comply, and procure that any third party it appoints to assist with any Audit complies, with Lendscape’s reasonable security requirements, the scope of which Lendscape shall notify in writing to the Customer prior to the commencement of any Audit.
10.6. Any records, data or information accessed or copied in the performance of any Audit will be treated as Lendscape’s Confidential Information.
11. Termination rights
11.1. Without prejudice to the exit arrangements in Paragraph 12 below, the Customer may also terminate this Agreement or relevant Service on 30 days’ written notice to Lendscape (or less notice where required by a Competent Authority):
11.1.1. if Lendscape is in material breach of Paragraph 9.2 to 9.5 above, and has failed to remediate such breach within 30 days of being notified by Customer;
11.1.2. where Lendscape is in material breach of this Agreement, or applicable laws or regulations in relation to the performance of its obligations under this Agreement, and has failed to remediate such breach within 30 days of being notified by the Customer;
11.1.3. where circumstances or impediments capable of altering materially the performance of the Services are identified by Customer (and they have a material adverse impact on the Customer), and Lendscape has failed to remediate such circumstances within 30 days of being notified by the Customer;
11.1.4. where material weaknesses are identified under this Agreement regarding overall risk management and the security, availability, authenticity, integrity and confidentiality of confidential, personal or otherwise sensitive data or information (and they have a material adverse impact on the Customer), and Lendscape has failed to remediate such material weaknesses within 30 days of being notified by the Customer; or
11.1.5. where the Customer is required by a Competent Authority to terminate this Agreement because the Competent Authority advises that it is no longer in a position to effectively supervise the Customer as a result of the provision of the Services or the contractual arrangements under this Agreement and this Regulatory Addendum, and the Parties are not able to agree within 30 days of a proposal by the Customer any required changes to the Services or this Agreement, each acting reasonably, to overcome any concerns or requirements of the Competent Authority or applicable law.
11.2. Unless such termination under Paragraph 11.1 arises from Lendscape’s material breach of this Agreement, Customer will pay Lendscape the Early Termination Fee set out in this Agreement within 30 days of giving notice to terminate.
12. Exit
12.1. Unless prohibited by Applicable Law or a Competent Authority, upon termination of this Agreement or any of the Services, Lendscape shall if requested by Customer in writing (at the time of any termination notice, or within 10 days of such notice being served):
12.1.1. continue to provide access to the Platform and the Services during the Exit Period, subject to (i) continued payment by the Customer of all relevant Charges and (ii) the Customer’s continued compliance with the terms of this Agreement;
12.1.2. provide reasonable cooperation to the Customer, and provide access to relevant non-proprietary or non-confidential information held by Lendscape, to assist it migrate to another supplier or to bring the relevant service in-house; and
12.1.3. provide the Customer with the Customer Data contained in the production environment of the Platform, in a standard format, or by prior agreement with the Customer facilitate a suitable channel to deliver the Customer Data held in the production environment of the Platform.
12.2. If Lendscape has terminated the Agreement due to the Customer’s material breach or non-payment pursuant to Clause 16 of the Platform Terms, the Exit Period will be reduced to 6 months and the Customer shall pay for the continued access to the Platform and any exit and migration assistance monthly in advance (failing which Lendscape may suspend the Services and discontinue exit and migration assistance).
12.3. If requested by Customer, the Parties shall document an exit plan, based on Lendscape’s standard form approach, setting out the various roles and responsibilities of the Parties to effect an orderly exit and migration away from the Platform and Services (both where there is an unplanned failure or insolvency, or a planned and managed exit) (“Exit Plan”). Each Party shall act reasonably and in good faith in agreeing the Exit Plan and any updates required thereto at a later date, and once agreed the Parties shall comply with the Exit Plan if this Agreement is terminated.
12.4. Unless otherwise specifically provided for in this Agreement, all exit and migration assistance will be charged to the Customer at the Lendscape Hourly Rate, together with any reasonable expenses. Where requested in writing by Customer, Lendscape will provide Customer with an estimate of the cost of such exit and migration support.
12.5. Notwithstanding the provisions of this Paragraph 12, the Customer acknowledges that the successful migration and exit from the Platform and Services is contingent on the Customer and any replacement supplier, and Lendscape does not take responsibility for the exit and migration activities, over which the Customer or its replacement supplier is ultimately responsible.
This Data Protection Agreement forms part of, and is subject to the terms of, this Agreement.
1. Definitions
1.1. The following definitions and interpretation apply in this Data Protection Agreement. Capitalized terms used but not defined below have the meanings ascribed to them elsewhere in this Agreement.
Business means, where required by applicable U.S. state privacy law, an entity that determines the purposes and means of Processing Personal Information.
Customer Personal Information means any Personal Information Processed by Lendscape or its Sub-processors on behalf of the Customer Group under this Agreement.
Data Subject means, where required by applicable U.S. state privacy law, a natural person who is a resident of the relevant state acting in an individual or household context.
Data Protection Laws means, to the extent applicable to Customer and its use of the Services, the U.S. federal and state privacy and data protection statutes, regulations, and binding orders, each as in effect from time to time and as enforced by any regulatory agency or governmental authority with jurisdiction over Customer, including without limitation: (i) comprehensive U.S. state privacy laws and their implementing regulations, to the extent applicable; (ii) the Gramm‑Leach‑Bliley Act (15 U.S.C. §§ 6801–6809) and implementing regulations, including the Interagency Guidelines Establishing Information Security Standards and the FTC Safeguards Rule (16 CFR part 314), to the extent applicable; and (iii) U.S. state data breach notification laws applicable to Personal Information.
Disclosure (and Disclose) means releasing, transferring, sharing, providing access to, or otherwise making Customer Personal Information available by any means to any person or entity other than (a) the party that provided or made such data available, (b) its affiliates, and (c) their respective employees, contractors, and agents acting under a duty of confidentiality, and, in Lendscape’s case, its authorized Sub-processors engaged in accordance with this Schedule.
Personal Information means information that is linked or reasonably linkable to an identified or identifiable natural person and that is regulated as “personal information,” “personal data,” or an analogous term under Data Protection Laws, to the extent processed by Lendscape on behalf of Customer in connection with the Services. Personal Information does not include de-identified or publicly available information to the extent excluded by Data Protection Laws.
Process or Processing means any operation or set of operations performed on data, including collecting, recording, organizing, storing, using, disclosing, transmitting, or deleting.
Processor means, where required by applicable U.S. state privacy law, an entity that Processes Personal Information on behalf of a Business/Customer pursuant to a written contract and subject to the restrictions required by such law.
Security Incident means a confirmed unauthorized access to, or acquisition of, Personal Information or Customer Data in Lendscape’s possession or control that compromises the security, confidentiality, or integrity of such data; Security Incident does not include unsuccessful attempts or activities that do not compromise data, such as pings, port scans, blocked malware, or unsuccessful login attempts.
Sensitive Data means: (i) “Sensitive Personal Information” as designated under applicable U.S. state privacy laws; (ii) protected health information regulated by HIPAA (PHI); (iii) biometric identifiers or biometric information regulated by applicable biometric privacy laws; (iv) personal information of children under 13 regulated by COPPA; or (v) any other category of Personal Information designated as sensitive or subject to heightened protection under the Data Protection Laws.
Sub-processor means a third party engaged by Lendscape to carry out processing activities in respect of the Customer Personal Information.
2. Interpretation
2.1. The Parties agree that the Customer (or a member of the Customer Group) is a Business and Lendscape is a Processor in respect of the Customer Personal Information processed pursuant to this Agreement.
2.2. Both Parties shall (and the Customer shall procure that any relevant Business within the Customer Group shall) at all times comply with their respective obligations pursuant to Data Protection Laws in connection with the Processing of the Customer Personal Information, and the Customer shall ensure:
2.2.1. all instructions given to Lendscape in respect of the Customer Personal Information are given in accordance with Data Protection Laws; and
2.2.2. any Customer Personal Information it makes available to Lendscape for Processing under this Agreement has been collected and made available for Processing in accordance with Data Protection Laws.
2.3. Lendscape shall Process any Customer Personal Information in accordance with the obligations of Processors under Data Protection Laws.
3. Lendscape as Processor
3.1. The Processing of the Customer Personal Information by Lendscape pursuant to this Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of Personal Information and categories of Data Subjects set out in Annex A to this Schedule 6 (Data Processing Details).
3.2. Where Lendscape Processes Customer Personal Information on behalf of the Customer (or a member of the Customer Group), Lendscape shall:
3.2.1. unless required to do otherwise by Applicable Law, Process the Customer Personal Data only on and in accordance with the Customer’s instructions as set out in this Agreement, as updated from time to time (‘Processing Instructions’);
3.2.2. if Applicable Law requires it to process Customer Personal Information other than in accordance with the Processing Instructions, notify the Customer of any such requirement before processing the Customer Personal Information (unless Applicable Law prohibits such information on important grounds of public interest);
3.2.3. maintain the confidentiality of the Customer Personal Information and ensure that persons authorized to process the Customer Personal Information have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; and
3.2.4. not disclose the Customer Personal Information to third-parties unless the Customer or this Agreement specifically authorizes the disclosure, or as required by Applicable Law (and if Applicable Law requires Lendscape to process or disclose the Customer Personal Information to a third-party, Lendscape shall first inform the Customer of such legal or regulatory requirement and give the Customer an opportunity to object or challenge the requirement, unless the Applicable Law prohibits the giving of such notice);
3.3. If Lendscape considers that any instructions from the Customer relating to the Processing of Customer Personal Information may put Lendscape or its Sub-processors in breach of Data Protection Laws, Lendscape shall notify the Customer and shall be entitled to suspend that Processing until such instructions are resolved between the Parties acting reasonably.
3.4. Lendscape shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Information against accidental, unauthorized or unlawful destruction, loss, alteration, disclosure or access. Such technical and organizational measures shall be compliant with Applicable Laws and good industry practice and shall at least be equivalent to the technical and organizational measures set out in the Customer Security Controls and Fair Use Policy.
3.5. Lendscape shall, at the Customer’s reasonable cost, promptly provide information, cooperation and other assistance reasonably requested by the Customer (taking into account the nature of the Processing) to assist in its compliance with its obligations under Data Protection Laws, including with respect to:
3.5.1. responding to requests from Data Subjects’ exercising their rights;
3.5.2. security of processing (including with any review of security measures);
3.5.3. data protection impact assessments; and
3.5.4. any remedial action, complaint or request relating to the Customer’s obligations under Data Protection Laws relevant to this Agreement.
3.6. Lendscape shall notify the Customer in writing, without undue delay, if it receives any written complaint, notice or communication that relates to its Processing of the Customer Personal Information under this Agreement.
3.7. Lendscape shall assist the Customer in responding to requests from the Customer’s Data Subjects exercising their rights under Data Protection Laws. Upon receipt of a written request from the Customer, Lendscape shall:
3.7.1. provide relevant information or access to Customer Personal Information within legally required timelines;
3.7.2. cooperate with the Customer to apply any necessary redactions or formatting;
3.7.3. implement a “stop-the-clock” mechanism in the event that further clarification is required from the Customer; and
3.7.4. ensure that any assistance provided is reasonable and proportionate to the scope of the request.
4. Sub-processors
4.1. The Customer provides its authorization that Lendscape may engage the Sub-processors set out in Annex A to this Schedule 6 (Data Processing Details) to process Customer Personal Information under this Agreement.
4.2. Lendscape shall notify the Customer of any changes to the Sub-processors engaged (and shall update the list on Conveyor), and the Customer shall have 30 days to raise reasonable objections to the appointment. If Lendscape and the Customer cannot resolve any such objection in accordance with clause 21 of the Platform Terms, then the Customer may terminate this Agreement by giving written notice to Lendscape and the Early Termination Fee shall become payable.
4.3. In respect of the Sub-processors, Lendscape shall enter into sub-contracts that impose on the Sub-processor materially the equivalent obligations as this Schedule 6. Lendscape shall remain liable to the Customer under this Agreement for all the acts and omissions of each Sub-Processor as if they were its own (subject always to the relevant limitations on liability set out in this Agreement).
5. Security Incident
5.1. In the event of a Security Incident concerning the Customer Personal Information whilst under Lendscape’s Processing (including in the Platform), Lendscape shall:
5.1.1. notify the Customer without undue delay and within 24 hours of becoming aware of such Security Incident:
5.1.2. make available information reasonably required by Customer (or any relevant Affiliate) to comply with its obligations under the Data Protection Laws to assist with their reporting obligations, taking into account the nature of the Processing and information available to Lendscape; and
5.1.3. promptly take all reasonably necessary steps to seek to contain and mitigate the impact of the Security Incident.
5.2. If there is a Security Incident for which the Customer or any of its third parties are responsible for, Lendscape shall provide its reasonable cooperation to the Customer at the Customer’s reasonable cost.
6. International Disclosures
6.1. Lendscape shall not Disclose any Customer Personal Information to any third party in a country or territory outside the United States of America unless Lendscape has ensured that (i) the location benefits from an adequacy decision under Data Protection Laws; or (ii) appropriate safeguards are put in place.
7. Return or destruction of Customer Personal Information
7.1. Lendscape shall, as soon as reasonably practicable after termination or expiry of this Agreement, and no longer than ninety (90) days, at the Customer’s choice, either delete (beyond normal use) or return to the Customer all Customer Personal Information in the control of Lendscape, except to the extent storage of any such data is required by Applicable Laws. Any retrieval or return of data from Lendscape to the Customer shall be undertaken using an agreed secure transfer protocol and machine-readable, structured data format.
7.2. If any law, regulation, or government or regulatory body requires Lendscape to retain any documents, materials or Customer Personal Information that Lendscape would otherwise be required to return or destroy, it shall provide the Customer on request with details of the retention requirement, and shall maintain any Customer Personal Information in confidence and in accordance with this Schedule 6 whilst the obligation applies.
7.3. Any deletion of Customer Personal Information by Lendscape shall use secure erasure methods compliant with NIST SP 800-88 or equivalent. Lendscape shall provide written confirmation of deletion upon request by the Customer.
8. Records and audit
8.1. Lendscape shall keep detailed, accurate and up-to-date written records regarding any processing of the Customer Personal Information, including the access, control and security of the Customer Personal Information, the processing purposes, categories of processing, and a general description of the technical and organizational security measures referred to in Annex B to this Schedule 6 (Technical and Organizational Security Measures).
8.2. In addition to any information and audit rights elsewhere in this Agreement, Lendscape shall promptly make available to the Customer (at Lendscape’s option, via the Lendscape Trust Centre for self-service by the Customer, or otherwise) such information as is reasonably required to demonstrate Lendscape’s compliance with its obligations under this Data Protection Agreement and the Data Protection Laws, and shall at the Customer’s reasonable cost allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
9. Parties as data controllers
9.1. Lendscape and the Customer (and their respective external service providers and/or Affiliates) may process Personal Information of the other Party as a Business for the sole purposes of the execution of the present Agreement.
9.2. If, during the term of this Agreement, the Parties agree in writing to conduct a discrete Processing activity for which they will jointly determine the purposes and means, they will first execute a written data-sharing or joint processing arrangement that (i) allocates responsibilities for compliance (including Data Subject rights handling and Personal Information Breach notifications) as required by applicable Data Protection Laws, and (ii) does not expand either party’s rights to use the Personal Information beyond what is expressly permitted herein.
9.3. To the extent a Party acts as a Business in relation to Personal Information of the other Party, it shall comply with all Data Protection Laws in respect of any such processing as a Business. Lendscape’s Privacy Notice is available online: Privacy Notice
10. Data protection contact details
10.1. The Parties respective contact details for data protection queries is set out in the Order Form. All privacy related queries should be directed to the other Party’s data protection contact in the first instance.
1. Nature and purpose of the processing:
1.1. Processing in accordance with the rights and obligations of the Parties under the terms of this Agreement, and as reasonably required to provide the Services.
1.2. Processing as initiated, requested or instructed by users of the Platform in connection with their use of the Services in a manner consistent with this Agreement.
2. Duration of the processing: Until termination of this Agreement and deletion or transfer of data in accordance with the Customer’s instructions pursuant to and subject to the terms of this Agreement.
3. Categories and type of Personal Information: First and last names, titles, business contact information, job titles, company name, email address, telephone number, business address, connection data and localization data
4. Categories of Data Subjects:
4.1. Customer’s employees, contractors, agents, users authorized by the Customer to use the Services, who are natural persons.
4.2. Customer’s clients, debtors, end-users of the Customer’s products or services, who are natural persons.
5. Sensitive (special category data):
5.1. No special category data is in scope for this Agreement.
5.2. If the Customer subsequently requires that Lendscape process any Sensitive Data via the Platform, the Customer shall notify Lendscape in writing prior to uploading or processing any Sensitive Data. Upon such notification the Parties shall agree, prior to the commencement of processing, appropriate additional safeguards (where appropriate, subject to the Parties agreeing additional Fees) to ensure compliance with Applicable Law, including, without limitation, HIPAA, COPPA, and Data Protection Laws.
6. Approved Sub-Processors: As set out at: Sub-contractors and sub-processors
1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood for the rights and freedoms of natural persons, Lendscape shall implement appropriate technical and organizational measures as set forth in the Customer Security Controls and Fair Use Policy and in any case to ensure a level of security appropriate to the risk.
2. Lendscape shall ensure that technical security controls are implemented and certified to the ISO 27001 standard.
3. Independent verification of Lendscape’s technical security controls and operational controls is available in Lendscape’s SOC 1 and SOC 2 reporting.