Loading...
HomeMy WebLinkAbout20-114 - ESO Solutions, Inc - Fire and AID Reporting SoftwareDocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 City of Tukwila Contract : 20-114 Number: 6200 Southcenter Boulevard, Tukwila WA 98188 Council Approval N/A CONTRACT FOR SERVICES This Agreement is entered into by and between the City of Tukwila, Washington, a non -charter optional municipal code city hereinafter referred to as "the City," and ESO Solutions Inc. hereinafter referred to as Contractor, whose principal office is at 11500 Alterra Parkway, Suite 100, Austin, TX 78758. WHEREAS, the City has determined the need to have certain services performed for its citizens but does not have the manpower or expertise to perform such services; and WHEREAS, the City desires to have the Contractor perform such services pursuant to certain terms and conditions; now, therefore, IN CONSIDERATION OF the mutual benefits and conditions hereinafter contained, the parties hereto agree as follows: 1. Scope and Schedule of Services to be Performed by Contractor. The Contractor shall perform those services described on Exhibit A attached hereto and incorporated herein by this reference as if fully set forth. In performing such services, the Contractor shall at all times comply with all Federal, State, and local statutes, rules and ordinances applicable to the performance of such services and the handling of any funds used in connection therewith. The Contractor shall request and obtain prior written approval from the City if the scope or schedule is to be modified in any way. The Contractor shall perform services in accordance with the Exhibit B, Data Protection and Security, Vendor Security Requirements and Service Availability. -100 11.." 01.19 mi • • 3. Compensation and Method of Payment. The City shall pay the Contractor for services rendered according to the rate and method set forth on Exhibit A attached hereto and incorporated herein by this reference. The total amount to be paid shall not exceed $17,296.55 at a rate of N/A. 4. Contractor Budget. The Contractor shall apply the funds received under this Agreement within the maximum limits set forth in this Agreement. The Contractor shall request prior approval from the City whenever the Contractor desires to amend its budget in any way. 5. Duration of Agreement. This Agreement shall be in full force and effect for a period commencing, November 5th 2020 and automatically renewing for one year terms as further described in Section 6 of Exhibit A, unless sooner terminated under the provisions hereinafter specified. 6. Jndependent Contractor. Contractor and City agree that Contractor is an independent contractor with respect to the services provided pursuant to this Agreement. Nothing in this Agreement shall be considered to create the relationship of employer and employee between the parties hereto. Neither Contractor nor any employee of Contractor shall be entitled to any benefits accorded City employees by virtue of the services provided under this Agreement. The City shall not be responsible for withholding or otherwise deducting federal income tax or social security or contributing to the State Industrial Insurance Program, or otherwise assuming the duties of an employer with respect to the Contractor, or any employee of the Contractor. IERZ22c7i • tiddR4Pifikep4 .a916 Page 1 of 5 1/1 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 7. Indemnification. The Contractor and City agree to comply with the indemnification obligations set out in Exhibit A. 8. Jnsurance. The Contractor shall procure and maintain for the duration of the Agreement, insurance consistent with the requirements set out in Exhibit A. 9. Record Keeping and Reporting. A. The Contractor shall maintain accounts and records, including personnel, property, financial and programmatic records which sufficiently and properly reflect all direct and indirect costs of any nature expended and services performed in the performance of this Agreement and other such records as may be deemed necessary by the City to ensure the performance of this Agreement. B. These records shall be maintained for a period of seven (7) years after termination hereof unless permission to destroy them is granted by the office of the archivist in accordance with RCW Chapter 40.14 and by the City. 10. Audits and Inspections. The records and documents with respect to all matters covered by this Agreement shall be subject at all times to inspection, review or audit by law during the performance of this Agreement. Notwithstanding the foregoing and except to the extent required by applicable law, in no event shall the City or its auditor be permitted to view, access, or retain (or potentially view, access, or retain) information which Contractor reasonably determines: i) is a risk to the security of its software if exposed; ii) pertains to its software or services and is proprietary, trade secret, or protected by copyright law; or iii) constitutes the protected information of Contractor's other customers, including but not limited to Protected Health Information, as defined by applicable federal law. 11. Termination. The termination of this Agreement is governed by the terms of Exhibit A. 12. Discrimination Prohibited. The Consultant, with regard to the work performed by it under this Agreement, will not discriminate on the grounds of race, religion, creed, color, national origin, age, veteran status, sex, sexual orientation, gender identity, marital status, political affiliation, the presence of any disability, or any other protected class status under state or federal law, in the selection and retention of employees or procurement of materials or supplies. 13. • I II ' I • I • . The Contractor shall not assign or subcontract any portion of the services contemplated by this Agreement without the written consent of the City. 14. - -11 i/ • • • 11. This Agreement, together with attachments or addenda, represents the entire and integrated Agreement between the City and the Contractor and supersedes all prior negotiations, representations, or agreements written or oral. No amendment or modification of this Agreement shall be of any force or effect unless it is in writing and signed by the parties. 15. If any term, condition or provision of this Agreement is declared void or unenforceable or limited in its application or effect, such event shall not affect any other provisions hereof and all other provisions shall remain fully enforceable. The provisions of this Agreement, which by their sense and context are reasonably intended to survive the completion, expiration or cancellation of this Agreement, shall survive termination of this Agreement. 16. Notices. Notices to the City of Tukwila shall be sent to the following address: City Clerk, City of Tukwila 6200 Southcenter Blvd. Tukwila, Washington 98188 tEIRIZ221c .d.R4 16 Page 2 of 5 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 Notices to the Contractor shall be sent to the address provided by the Contractor upon the signature line below. 17. Applicable Law. Venue: Attorney' s Fees. This Agreement shall be governed by and construed in accordance with the laws of the State of Washington. In the event any suit, arbitration, or other proceeding is instituted to enforce any term of this Agreement, the parties specifically understand and agree that venue shall be properly laid in King County, Washington. The prevailing party in any such action shall be entitled to its attorney's fees and costs of suit. 18. Conflict in Terms. In the event of a conflict between the terms of this Agreement and the terms in any other document, including but not limited to Exhibits A through D hereto, the terms of this Agreement shall prevail. Exhibits: Exhibit A: ESO Terms and Conditions Exhibit B: Service Level Agreement Exhibit C: Vendor Security Requirements Exhibit D: Information Security Policy teiR.z2R .d.R4 . 6 Page 3 of 5 DocuSign Envelope IIID: 61E11B861E8-31DIE8-41B21E-9549-CIF9859A53513 DATED this 5th day of CITY OF TUKWILA C-4(Leuc .65r/e'g November Allan Ekberg, Mayor 11/05/2020 ATTEST/AUTHENTICATED: C1h4.€ 6,677(cth&tr-J y Clerk, Christy C)"Flaherty APPROVED AS TO FORM: ./Hdlg 6-/C(�fCP/! Office of the City Attorney 20 20 . CONTI ACTC R DacuSigned by: tuff Raw By: Printed Name and Title:Matt wad ker c©© Address: 11500 Alterra Parkway Suite 100 Austin TX 78758 (ERL22CiN.. 3 6 Page 4 of 5 DocuSign Envelope OD: 6E 119861E8-3DIE8-41921E-964 9-CIF9869A6361 3 MATER 5 U D5cRIFT ION ANQ LICENSE At5REEMENT Tliros 1Mister Subscrokotoon and Louse Agreement (thos 'Agreement ) os entererl onto as or ("Effective Date' ), ION and oetween E50 Sollutoons, 000 a Texas corporatoon liravong ots proncopall place of Lus 000101 at 11500 Aaerra Parkway, Suote 100 As1 0, TX 78758, oncloi ong Its controller! sultosorl oa nes, (colIllectovelly, 'ESCI ) aria CootyoTTo w 01 Wa str 05100. ruv 05 ots prom:opal pllace 01 410000101 011 6200 Soutlircenter Oou e,oirrl, Tull,wolla WA 98188 ('CustOmet ) Thos Agreement 00001 0101 01 8:0 Generall Tenns 1 Conlotoons lbe)ow and any Arlo:tern (as a eroner) bellow) 04.00 :104 ION the partoes, :0) 05 any attaclir 0:00101 10 01 041 Alia len a a INC panties litave Deer! that. 1E50 will prey de Co.istom 00 centa On 1004100 054 proclucts uorl/or servOces and that 41 :0100:00 wall pay 1E50 certa On fees. Therefore, On consOct eration of the covenants agreements a it ci prom Oses 0101 100141 bellow, a na for other 5000 and valluablle consOoleration, INC receipt 01041 so.iffkalency of 'wh01: Os herelby 010) 00W INC parties OntenclOng to be legally 10 (XI 3 herelby agree as f ollows. GENERAL TERMS AND CONDITIONS DEFINITIONS. Caotalkzect terms not otherwise clekinea On 141 01 Agreement shall :0130 8:0 meanings lbellow "Add -On Softwaremeans any compllernenta rY S 013t.W3 e components 00 reporUng servOce(s) that 1E50 makes available to customer through as ILOcensea Software Onterokeratalty Software or Saa5. "Addendum" means a writing a aaressing an orcier 0101 specOtic set of mat:lots or 001/ 0001 executer] by 0111.541onized representatives of each party. An Actaencloim may be (a) a Software Scheaulle, (b) a Statement of Walk (c) Sales Order, 00 (a) another molting the parhes 010041 10 be Oncorkoratea by reference Onto this Agreement. "Anonym/Zed Data' means C 4.1 St. orn er 1Data from whOclit all personally 110014 01119 Onformation 10tas teen removed, as well as the names and addresses 01 Coistomer n0.1 004 01 as Users a roci/or Co.1 stoiner s cllOents (0104 wlinich, as a consequence, Os neither P1 nor Oc)entaliablle to or toy Customer). "Contract for Services" means tile agreement to provOcie the seroices clescribell below, executed lbetween 1E50 and the Customer, to whOch Viols Master Sulbscolphon and LOcense Agreement Os attachea. "Customer Data' means Onformation data and' other content On ellectrornic form that Os subrn Otter! poster!, or otliletwOse tra rosin Otter! by 00 on 1101:011 of Customer trtrortgn INC Software. 'Delbefable• ineans software, report 00 other 'work. °irorluct createcl fiursuant to a Statement of Work.. "50cumentation" means user 50 0)90 operating man ‘.1 3 S and specalications 00501010:5 11:0 Software. "Feedback' 001005 10 any suggestion or Oct ea for OmprovOng or otherwise mor11yin5lE50's [10001 :010 00 servOces. "Incident' refers to a 11001'0er! and o.iplloadecl record withOrt the system on a per- encoointer basis, regain:Hess 01 11:0 ruirrober of patients Onvollyea On saia 0111O1/icluall encoo.inter. "Intellectual Property means trate secrets, copyri g luta 1 e subOect matter, patents a roc! patent a poillOcations, arta other propoletary 'information, a ctOylties, and any lit:leas, concepts, 'innovations 'inventions a na res 505 "IntemperabllitySoftware" means Sa a5 that allows Customer to exchange lileallthca re clata with others. For the avoliciance of cloubt lInteroperab011ay Software aoes not Ono° U ole Aact-on Software or ILOcenseci Software. "Licensed Software means INC executablle object 000)0 '/0S 001 of software that 1E50 provOcies to C Ustorner for 015 oise niolrl Onstallllahon astern er s own ecortiOkanent. Por INC avhiciance of a oubt, ILOcenseci Software oloes not O 111 COU3e Acia-on Software, lInteroperahilliity software or Saa5. ILOcensect Software Sita not Onolluole software that stores protecterl Ireno Itr nformation. "New Version" means any new 'version of ILOcenser! Software that 1E50 may from time 101ine Onto:Douce and market. generally as a clOstinct °licenserl proclo.ict as may be OnolOcatea toy 1LOcensor's rlCsOgnation of a new /CO 001 number Ibranol 0) 10001 "Outage means Customer Os oinablle to access SaaS, or such access Os m aterlia Hy delayed Ono pa Oreci or clOshiptel, On each case as C3‘.1se0t or controller! toy 1E50. "Professional SeIvIces r ieniTh prof essionall services provOaer! by 1E50 unct er ni Statement of Work. • Protected Health Information' or 'PHI sIir ni tr ni ve 11:0 rr ea non g set root P in 1111PAA All references lir ere 0110 PO shall be construed to on cloo019 electron o 0 P11111, or as tlio at term os rlcron ea by 11 ilIPAA {ERZ2238117DOCX2/13175.000012/ ) ▪ RepOrting Services' means collectrvelly INC °inherent toolls oo: features On the Softwa re a ow r: Customer 10 eocrni1e corr011altions of clata, Oncluchng but not IlanOter! to aocl-litoc reports arnallytics, lbenchrnarling or any other repontiolg tooll provOclecl through the Software. ▪ 5985' means softwa re -a s-a-servOce that. 1E50 10tosts (c!Orectly or Onc)Orectly) for Customers use. 1E0o:the avoOciance 01 cloubt, SaaS cloes not 'include licensed Software, tout cloes 011011 ogle Ada -on Software and Onterop era to011Oty Software. "Scheduled Downtime means per°000 Mien 1E50 'intentionally Onterrohits the Saa5 for the performance of system rna Ontena nce or to otherwOse correct 503 00 errors. "Software' means any 1E50 computer program progra min On g or m oclulles specalied On any Software Schectulle or SOW. 1For the avoOrlance 01 0101:11 Ar.ta- on ,Softwa re SaaS lInteroperato011ay Software, and LOcensel Software are collect elly referrerl to as ,Softwa re. 'Software Schedule" refers to an Actolenclum uncle: 'Million' Customer 101a s oraered entlitter Aria -on Software, Ucensel Software, lInteroperab011Oty Software or Saa5. "Statement of WON or "SOW refers to an Aclaertaurn Oro 'which Coistomer trris orclered 1ProfessOpnall ServOces or a Dellrverablle from 1E50. "SupoOr I Services' rneans those servOces clescrlibea On jr 11 1B. " Third -Patty Date! means clata not owner! toy 1E50 but 'whOclit Os (or access to Million' Os) provOciel by 1E50 ol 111 3 er a Software ,SchectU Ile. 'Thitti-PailySerVic6f means a service not. D/ 01001 by 1E50 but whOclit Os (or access to 'wh041 Os) offerel toy 1E50 On connection w04 Ir as Software unrler ri Softwa re Scheltale or Addendum • rhird-PartySoftwa al lir iCrioo sortwa o 0 not owner! toy 1E50 tioit Wtr Otros (or 000000 10 whoclir 00) 0000vorlerl toy 1E50 uorler ri Software Scher:tole or Allenaoion ' Use Restrictions' means the restr0Ocons Oo n)00104 00 Customer's use of Software as a escrObea r SectOon 3 3 'USW means 33 5.° eciMicluall 'who oases the Software on Customer's lbelitallf or throt.igh customer's ri Coo:nt or pa ssworas, 'whether authorizer! or root. SOFTWARE ORDERS. Do.ining the Term, Coistorner may orcier Software from 1E50 toy signong an appropriate Software , Schectulle. Customer's cense to Licenser] Software arta Ots sulbscriphon to Saa5 are set forah bellow. 1E101 soich Software ,Sclitecloale Oncorporateci 10terein by reference. 3. LICENSE/SUBSCRIPTION TO SOFTWARE 3.1. gg012"5110grillLarl,:ig„g„fi. For ,Sa a 5, duningtheTerm C :IorriCr may access and use INC ,Saa5 atoll Reporting Services On such quantOties as are set forth on the prollOca be Software ,Schecloille, 01 :1(001 to Coistorner's corn pla nce with INC Use Restnicotions a roc! other Ito contauinea On tours Agreement. 3.2. golgutooguLgerot§s000 joLigerisertSlonEageot. Por Licenser] Software, clurfolg INC Term 1E50 hereby grants Customer a IlOrnOtel, non-ei.clusrve, non- transferablle norkassOgnable nort-sublOcensable revocalble IlOcense to copy and use the Licenser! Software, On such q ‘.13111tAli es as are set forth on INC applhicatolle Software Soite-lute moil as necessary for Customer's 'internal° business purposes, On eaclio case sulbject to Custorner's compliance 'Milt the 'Use Restnictions rind other IlanOtaltions and oblgatoons remarried On IOUs Agreement. 3.3. Use 1Pestrictions. lElocept as provOclea On tlitis Agreement or as otherwise at.itlilorOzeci by 1E50, Custorner trrio no r tr1 to, ancl 0hal111 not (a) clecornp011e, reverse englneer, cfisasserntolle, [mint cow or clisplay the DocuSign Envelope ID: 6E11B861E8-3DIE8-41B21E-9549-CIF9859A53513 Software or otherwise rect ‘.1 ce tItte Software to a lir UrIooipercenva He fond] On wholle or On part(to) poibtish rellease rent.°easelloan sell distrOtoute or transfer the Software to a notItter person or entlity; (0) retoroct ‘.1 ce Software for ltItte use 000 benefOt of anyone other than Customer(0) alter, motility or create ctertvative wcwts toasect upon the .5oftwa re either On owholle 000 On toarto or (0) use 000 perm a the use of the Software for corn 1111 Urn e-sha ning arrangements or providing senbice burea atal pr cessiing, rental°, 000 other 000/000to any 1)1 01 party (On011‘.1 ng arty aftillrialte not specriticallyllOstect Oro the a 001 tolle Software Schectulle). 3 nil Own eo slt r op The rights go ant el uorI er INC o oo o/ 0 000 01 this Ago eement 0 co not c000stototte salle ot tltre 5011wa re E50 o eta on s all oogltrt, totlle anti onteo est on and to INC Software orb:Ow-tong wolthoo0 lloonotation 0 sontwaoe insert to 000 °vole the Sottwa oe oOO all go a o)h ocs user tert ces, llogos anti to a cleona Ils oeo)oottoicel thoough INC Solt wao e etcept to INC lloonotel extent set tooth on this Agoeeonent This Ago eement loes not err ant Corstoorrer any oole011ectorall poopeoty rogltrts oro INC 501twaoe oo any 01 °its cooriponeolts etcept to tltrelloorrotect ettent tltrat °this Ago eeorrent sooecotocally sets tool Or 000Irrrr ier s olIghts to access use or coiry INC Sottwaoe 11 rrong the 100:1 Cot stomeo inowlect ges that the Scott wao e anl °its coinponents are pootectel toy copyooght aral olt Irer awes 3 5 Priori -Panty Sottwao e 1010 Services IESO nelltreo accepts habollotty lor noo wan ants the tunctionalloty 1:1 1I! availlatoolloty oelloabolloty or acconacy ot Thoort-Paoty 5coltwaoe or Thoort-Paity Services INC Thool-Paoty5ottwaoe 'EMS1 Acaleony' anct/oo '111ooelRescotei Acatteony" anit/oo '1E11d51 IFooeRescorel Acaleorty -1:111 01:100131 1111 atal Contogot ration' anryor 'Lea rn on eNIooJEerrleoISvsIelrI oilO'Or EYAIL5 llorlpoeorrentaltoon' (001111001[ov elly Education' o s otteo el by 1E50 ori colllIal)ooration witltr L9'.o poll 1/11 ./a The 1Po a et oo oan oa000lot 1 3 :StOirier sulbscoolbes to lEctorcatoon, Custooneo adonowlertges and agrees 10 the teo ons anti cotillions ot the Praetor11011 000500°ago eenrent llocatect at lortLjr, 1,1P,"11 1),)V1/1 ricl,h2; A.21 /102-,NLi.21,1,.210, which shall sot peo sette this Ago eeonent os t Oslo Coistooneo's use 01 lEctoication anct any C 1:0101: ier Data stooel thereon 3 CI, Ttattit:ElgitYl DoIo t Customer (as onriocatert on an Allem-t11:0 000°1010 cense Thool-PaotylData g tore 00100) then subject to the teoons Ineoeot 1E50 Ineoeby go ants ClISIDIr er a tor:11-e tcllitsove non- subt censaltolle aral non -to ansterablle Incense rior the Tenn to use 51101: Thoort-PaotylData via the 5010twaoe sollelly lor Corstooneo° s onteonall pot rposes Customer m1111 not (o) allow E(reoler ccess than that sett tooth on INC 3)) 00)10 Sr:VA/aloe Scher -lode (op 0°5011000 re 0059 lostooltnote or Oe ver T)1oort-Pailty Data or any pontoon lIrercol to any HI oo party (000) copy molly or create rterovaltove woo )os ot T1:0o 0 -Party Data (tv) rent °ease 11000, sell 011)1 001150 assign, lostoobute pultollosh IroosIer or otherwise make avaollablle Thoort-Pailty Data (/) attempt 10 01:111:1 on any too on onooe than 10% ot the Thool-PailtylData oo otherwise coo colonvent the usage lloonotatoons on dot 0 el on the Sontwaoe (got o ern aye any )Ioopooetaoy notices on dor 0 et! mill on "Moo cl-Pa ty Data or 5ottwaoe or (voo) use Thoo 0-Pailty 1Doti on any trianneo orlor 1110)olopose that onto onges or oltInerwose voollates any poopooetaoy roght 01 3 person, or that voollat es ppoica blle Ilow 1E50 11005 not wao° ant INC tot n ct oon alloty relloabolloty a cool acy, coo 1 roolletten ess or ottolloty01 lIr rrtPoi1 Data or accept any lloabollotytheoetoo Allotoonall teoons anl lloor rotations appllocablle to Thoo 0- 1Pooly Data orray lbe po ovott el on lire ooplloca blle A1)OerrOiri blew Versions &Sunset Ontentoon ally Oonottel HOSTING, SLA & SUPPORT SERVICES 37 4, 11 riosbnE1 Custooneo 51:111111 be sollelly eS) onsoblle tor In °stool ganl onana n g any Locensel Sontwaoe 1115001:3ll toe oesponsoblle for lor nostong awl tanago IT 11110 51135 nit 2 Service Leve ll A r‘oeeonent 10 an 0 I11e 0.0lluctong Scher -tulle -1 1Downtoone (as 1)01 1:21) bellow) results on the service °eve° olpthlre tailing bellow 99 951', tor three iriorrltro on any oolong 12-ononth enot) (the tipt/me Commltmenr 1, then Coustooneo ray oononeloaltelly'teoononate this Agoeement in which case 1E50 woll rel :110 any 000epaor) unearned Fees Ir CusIolrIer or onay ottolloze the oemernes tlescootoel on 11»: 111 1.3. Soto P U V PCI Dowtione. IE50 w°1111 provOcle rea sorsa IbIle not 00 10 INC Customer (Software Actin Oroistrator Contact or ot): ermise) 01 Sctte1)o.11100 Downtime(usually at °east 72 lir otors On advance) anti w°1111 pllan Schectullect 1Downtione to occur °tubing oion-pea hotors (itictroright to 6 a.m. Central° Tittle). Soh ectullect El :0 shal111 never 001151O11,00 11 failure of oteolortnance 000 Outage toy ESO. {ERZ223811 7 DOCX,2/13 175 000012/ ) [ 4 5:1[po1t g,rtfliuprigt[eg Durong the Tenn, IESO shall provole to Coistonner the So°o)porot Services, on accordance mth Eirtrobot w: o: ns on corporat ect Orereon toy reterence 5 FEES 5.1. IFtees. Oro consideration of the nights granted Customer agrees to pay E50 any t.,intiOsputect fees for the Software and Professionall ServOces as set tort r On the Software Schedulle(s) or SOW(s) (collectively, • FeesP The Fees are non-cancellatolle and non-refundatolle, except as expresslly provOdect Ilierein. Customer slit al111 pay al111 Onvoices writhOn 30 days of receipt. 5 2 T):oott-PaotylPayer 1 L storier lesoo es to use a thoort-paoty to pay soone or all 0111r0 Fees on Itoeltr all ot Cot stoo n eo (a ThIrd-Porly Payet 1 then (o) each apppcablle ArliteHrhon wt1111 or)entoty sorch an an gement, (oo) the Thortl- Pa rolty Poer m1111 enter nto 11 woollen a grr eel! rient with 1E50 o ega rl on e s‘Idtr aooangeonent (000) Clustooneo may oepllace the Priori -Panty Payer by wootten n01°001[0 1E50 (poovortel that no such change shall toe onale orntoll the then -con oent Teo ons o ewall) anct (ov) Custooneo shall oeona000 resoos elor payment it the Thoort-Paoty Payer (1005 1101 pay the 1Pees 5 3 IlArittlottlacjacjw°411 Fees tor Sottwaoe wItrodr reot r 111111111011y stra1111 once ease by 3 each year this Ago eeonent os on etted 5.4. Taxes anti Fee5o. 11:0 1Pees are atoll ustv e of al111 to and crect a carol processing fees, 1311ltica blle. Unless ant! unt°11 Customer provOttes 1E50 a tax exemption certritciateCU stoiner will toe responsOtolle f000 anti will rebid (or w°1111 prom ottlly rerion burse 1E50 for) 1]1111 taxes 01 1110 tiolinct, I0 11(1 511 05 o.ose, cluty, custorns, owrithholltiring [property, iv all ‘e -al ect , and other sOrn rilllir 1000roll, state or °Doti° taiites (other 101111 taxes Ito s on 1E50s Orricorne) reiatect to °nibs Agreement.. 5.5). Atopr o O alb 00. of 1E1°,100 s.1 Cot stun er Os a city, cOlUnty or other government entty, al sterner MOO Ittave INC night to terrnOnate INC Agreement at INC enct of INC C stair ens Oscall term 0 Ciostorner provicies evOttence that. Ots governOrog botly 0O0 not a potroprOate s ff Odent funcis for INC next f scall year. Notorithsta nct ring INC foregolog thOs provOsOon shal111 not 0.0 50 3U stoner from past patyrnent otollOgations or other Fees ea r n ect anti to p a Oct. ILlsige jigotritobitgo CU st.orner Os sollelly restrensiblle for Rs own a tilirerence to voluble anti use °limitations Ondicatect on INC 1111101)lle Software Schecnolle. 1E50 may monitor Custorn ens use of the Software anti 0 Customers ‘sae exceects INC Ilev ell for oolirriclt° Customer Ott] s pa Oct Oro ttre oro orollOca tolle Software Sotrenlu Ile (an 0Verage), Custom er sh a 1111 rawe 1E50 INC 1Fee corresponding to such usage °eve ° lba sect 011he Software Schectulle (or 0 none, IESO's then -current. rates). 1150 may invoice for Overages lion mectriatelly. ri TERM AND TERMINATION 6.1. Lain- INC term01 thOs iAgreetnent (INC Ternfl sha 1111 commence on INC Effective Date anti contin e for INC penioct set loth in INC appolicatolle Software Schectulle (or Olt none, for one Yearly forovit)ect °that the Tenon shall be automatically extenctect 10 natch INC enct of INC Oast subscrOptOon penioct or hoense IC 00 01 1110 Software provictect irereuncter. Thereafter the Tenn will renew for successtve one-year peolocis u: CSS wbitten [notice Os provOttect atIleast 60 days oriY or to INC ppllOcablle renewal° Oate. 62. Termination for Ca se. lEither patty on ay term Onate thOs Agreentent or a roy roct riv ° 0111ll Software Soh et] Ulle for INC oth er pa rIty sUrIC ‘.1 re 0 on te ni1111 Ito re a ch toy 0/ 1) written notOce. INC rreootrO g tot] ity s a 1111 lir av e 30 clays from receipt of INC 'mitten notice to al re such oreach to INC reasonablle satisfaction of INC non-lbreachlo g party. 6..3.. lEffect of TermOnation.. 6.3.1. Of Clostorner teronniates this Agreement. or any Software Schedule as a result of IESO's mateniall toreach, then to INC extent that Customer Peas prepaitt any 1Fees 1E50 shall refunct to Customer any preparict Pees on a pro -rata basis to the extent such Fees are attnitoutablle to INC toetrioct after INC °otter to occur of INC (0 termOnabon (1ate or (0) INC Date on 'whic): Customer actually ceases U se of th e Software. 6.3.2. ILlotioin terrifirsaltrion of °this Agreement or any Software Schectulle, Cust.orner shall cease all use of INC Software anti 1)C ole clestroy or return all copies of INC 1Docurnentabon and Licensed: Software On Ots possession or contra °, except as requOrect toy Ilaw. C sterner shall remain oblgatect to bray apioropniate 1Pees at IESO's then-conient D o co Si g n Envelope ID: 6E 11B 86IE 8-3DIE8-41B 2IE-9549-C IF 9859A 53513 rates 0 Customer continues to use or access Software after the ternfinahon or expOratOon of trolls Agreement. 0 33 Teornonatoon 0110os Agreeonentos mothout poeporloce Ito any other rt or, r, emerly arml shall° not rellease panty !Noon any habolloty 6. De very of Data. Of Cust.orner requests Ots °rata withlin 60 clays of mopOration or termOnation of this Agreement E50 MOO provOrie Custorner 10000.!stornerlData On a seairotrail 0 p01 forrnat or such other format as the part es inutualry agree to. Customer a cknowllerlges that ESO ncter no obllOgation to retalin CustomerlDiata more than 60 clays after expOratOort or ternfinahon of this Agreement. 7 REPRESENTATIONS AND WARRANTIES 7..1.. 1Mateniall Performance of Software.. E50 re 10005/0 incl 'warrants that 11:0 Software MO peolorm On inatenall accorclance 'Miro any Domirnentation provOclecilbY E50.. 7..2.. lEach party's efo.ecultion 00/05/anct peoloronance of othOs Agreement and each agreement or Onstro.loonent contempllatecl by thOs Agreement has been Moly authorizer! by MO 110000005 /005/00010 or govern Roe rot O01 Oo n 7.3. A00t1iiong[Agagnite5:. 050 further represent.s as fo011ows 7.3.1. That the Software rioes 11101. C Iflitai lilt any vOruses 'instructions, routines, clemices keyllocks hme bombs orsOrn011ar rnech autism's that coull0 Misrupt Customer's use of the Software. 7 32 That all uplates upgoales, patches, oonpooveonents amol 11leo/ Re 00000 V/ 01001 0 wairrai11toes clesco obe0 110hos 4o'goeeor lent That 001V 1110010 upgoarle patch °orlon oveonent anl °Yew 009a00 won °orlon Dye 1110 won [not rerll:0000 ehorlonalte, Y funcotoon, Teatme or 011 00 present orn the Sofitwane at the °tome 01 °the uprlate upgoarle patch oonpooveonents amollInewo Release 7 7; 7 4 Coostooneo Cooperartoon Customer 110000510 000 ou00011t Operr 00 5/sten dnor oedsondblly dnor ton lelly coopeodte ml°111050, ornclloorlong provorion elE50 ed son d blle docess toots moo:p:lent sortwao e 1110 Oaitai rn ecessa oy tor theolllopllenientdotoon dnool opeo donor: of the Softwdoe DISCLAIMER OF WARRANTIES 5/00 001 AS OTII1ERWISE PROVIDED 11111 SECT11011'1 7 1E130 DISCLAIMS ALL WARRAINTOES 0100055 00 °IMPLIED 1111 ICLUID1111°Iu ALL 0100 00 "NAIRRAIIITOES 010 01ERL:11'1A° ITABOLOTT nTll 1E55 0005 RARTOCULAIR PURPOSE, rc 10E014,15110CE SUITABILITY, TOTILE, 11'10111- 111111FROINGEMEr IT OR 4111Y LIOL 00 'WARRANTY 401501110 mom STATUTE, COURSE or DEALING COURSE OF PERFORMANCE, OR lUSAGE OE TRADE W0711'101)17 00FIT-00°5/ T1 11EIR50T 0 or TIliE 000000 5/ ESO DOES 1110T IREPRESEll 5/ 00 "NAIRRAII IT IAT SOFTWARE pflo WILL PEREORM WITIIIOUTIIIIITERIPUIPT1101110R ERROR 1EXCE0T AS E00IRESSL r° PROVIDED 00 1 SECT11011 10 CUSTOIMER ACCEPTS PI SOFTWARE 'A5/115 Alr°10 5/5 AvAIIILABLE 10 118 OF T11.118 DISCLAIMERS COrITAIIIIIIED 1111,°1 T11,111SSECTOON 8 51 °ALL 1111°1 Al 10 'WAY PACT, I0100IIE0, 00 00550 °I All 00 000505 1E50 OBILIGAT1101115 OR LAB 00 ESTIAT DO 1140T COO ISPITUTE 'WARRANTIES UINIIDIER 0R00I5I0N1S 011,71°10S AuREEIMEINIT ONCLUID1111 °10 InUT 11'10T L LITEDTO TIE1E10EPT11011 „IS TO L1111).411TATI1011 IS 01111 LIABILITY C011,1TAIIII,IIED ISELT11011°1 12 3 9 CONFIDENTIALITY 9.i. "ConfidentlalInformatkan" refers lt.c) the followOng 00115' (a) any clocurnent marker] (b) any 110001111 001 0011 0>0100 00:11100 as 'ConfOrientiall" at 1>0 1:10 010lscllosure, roovOclecl the MisollosOng party confirms such clesOgnaltion Ool 'wolfing wOthOol fivelbusOness clays, (0)11:0 Software a roct1Docurn entahon 'whether ornot 000 00:11190 contirientia (0) ESO's securely controlls, koroceolures auclOts, 00 011:00 OnforrnatOon 000100001 00 Esas 'internal° 0ecun0y posture, (0) any other nono)ubllic, sensitive 'information reasonablly treater! as trade secret or olthetwOse conticlentiall, anci (1) CustomerlData 'wh01: 0005 not cornprOse 0011. 11"ootwOotrostanclOng the foregming ConfOrienhall Onforrnahon 0000 not 00 100 Onforrriation that. (.0 5 n the other roanly's possessOon at the Vine of rfiscllosure 11000 whOch Os not otherwOse restoictecl by a °fully of 01on- 01O5011051.100, (n) Os Oncle)enclently clevellorolecl wOthoo.)t use of or reference to Conficlentiall Onforrnaltion, MO) becomes known po.)bllOolly, before (ERZ2238117 DOCX, 2/13175 000012/ ) 0 50005)100, other than as a 000)00 of the receOvOng koarty's 'improper anon orOna cohort, 00(Ov) Os a kokorovec! for rellease On 'wnin ng by the clOscOoslin g party. 9.2. IfolonclO5005 100. lEach 111551111 1100 00:1 01001111 01 1110 other party sollelly to fullfO1111 1110 15/1115 of It.11tOs Agreement (the 'Purpose). Ealolr party shall (a) ens 41re that 05 ernplloyees or contractors are bouncl Iny cant OclentiallOoty obllOgatOns nollessrestrOctive than those contalinecl hereM, 15/0 (b) not clOscllose ConfOrientialllInf pro -nation to any other thOrcl party vothout )r 00 w001e01 consent from floe 01O501105Ong pa rolty. Without hinOting the genera IlOty of the foregoOng the receivOng party shall protect. 0001 01001 010011111 00 wOth the same clegree of care a 1505 10 protect Otos own conticlentiall 0100111111 001 01 sirruillar nature anci Ornpo0ance, but with 010 935 than reason ablle care. A receOvOng pa 0.y shall° promptly notlytlterlOs01105Ong oly 01any rn 51150 ormOsapproprOation 01 ConfOclentialllInforrifahon of 'wh011 el Os awa re. 9.3. TermOnation 1 Return. WOlt.11), 00011001 10 each Oterro of ConfOrientiall Onforrnahon the oblIO gati 01115 of nonclO501100)100 MOO terrnOnate three years after the clate 010O50110sure, 00/ 0000 that such obllOgainons rellateri 10 ConfOclentOalllInforrnahon constOltuhrolg ESO's tracte secrets 51111n 00011ino.10 00 00E) as such Woformaltion rerna Ons 501)001 10 tra rie secret protection pursuant. to a kokollOca bllella 'Upon terrnOnation of thOs Agreement, a koarolty 31111 09111001 111111 00 p 05 01 ConfOdentia1111111400rnatOn 10 1119 otheror certify the ctestruction tIltereof. 9.4. Ipplefitlfagouploo,05,. ThOs Agreement 0005 [not tralorsler own e r p of ConfOrientiallOnforrnation orgrant 11hcense thereto. 9.5. Open Reccorcls anct Other1Laws. NotwithstanciOng royroling On thos Section 10 1110 contrary, the [mollies expresslly acknowlleclge that Contirientiall Onforrnation may be clOscOosecl Of SU Ch Conticlenhallhiforrnation 001.111 0901 to 110 M00005001 1> 110/ 11 po111lIO00000005 request, or )olclOcOall orOer. The receOvOng party shall reasonablly coor)erate Oro) thos 011001 11 aciclOhomIESO acknowllerlges that trolls ifoogreernent Os a public 0100 111001 arta that Customer may M0011050 the contents of tins Agreement for the owoopose 01 0011)1 01 Ots revOew am1 approval° processes oincler 15 0011 nodes ancl consistent Miro nts treatment of other contracts. To the extent Customer 00001/03 11 specfific request public 0000000 rellatecl to Co.)stornefisIbusiness rellahonshOp walk E50 Customer MOO tose best e1100010notify 050 01 so.1011 request. 10. INSURANCE. Throughout the Terrn (am1 for a )enloc! 01 111 °east three 'years thereafter for any 0:3 10110:00 mitten on a 011aOrns-rn1l0le forrn) E50 shall mriOntann Oro effect the 'insurance coverage 010500 0001 bellow: 10.1. CorrnfiercOall genera° habillOoty 05 01100991111111111nirno.lin of $1 11 001 per 000))00ence anct $2 11 001 aggregate, Coofirrieraiall Genera° Liao MillOoty 015 10110100 shall° be as °east at War! a 5050 ocalrrence form CO 00 01 ancl shall° cover hab011Oty arlisnig from 10011 595 operah 01115, Onclekoenclent contractors, koroclucts-complleteri operations stop gap 111 1> personal° OrfOody anri aclveMshiglinnny, am1 liabillOoty assumeri 1010100 110 05 10001 contract. Co.)storner shall be namecl as 1111 a CM ntiO In an O015o.1090.1o1n0e0the Contractor's CoofirnercOall GeneraLiabillOoty 'insurance policy wallo respect to the work. ))0000mect for CustomerusOng1150 AMIMonallOnsurerl enclorsernent CG 20 10 10 01 1100 AcIchltionall Onsurecl-Cornplletect 01100111 0010 enclorsernent CC) 20 37 10 01 00 substitute enclorsements provaing at °east as broacl coverage. 10.2. AltorIDO OLJ1 10OnsurancewOth a rruirtOrrwlin corntoOnecl sOnglle IlOofi11. for boc1011y 0) 100 am1 property ctappage of $1,000,000 per acdrient. Ao.)tornob011ehab011ely Onsurance shall° cover Weil and renter! veroOdes. Coverage shall be 'wrtten on Onsurance 501/ 093 Office (1150) form CA 00 01 00 11 sulbstitute form provOriOng 01.1111/11 0011 11 b011ely coverage. Of necessary the 110 00 shall be 0)1000000 to roirovOrie contractuallhabillely coverage.1E50 specOlicallfy' ai Er eS tlrot 1 shall° root oo.159 any autornob011e owner! or 0a1500 10 ESO 10111 1 any oll.111Ogati0015 under thOs Agreement 10.3. Worker's compensation coverage as regolOrecl by thellro0)1Sti ai Orrisurance Ilaows of the State of WosIr El0Ol l0 10.4. Computer r)rocessor/corroputer p001e550011llIllia00110y Ons‘1031111Ce (o/ '11 technollogy errors 11010 011 550015) coveting thellOallo011Ooty for 1 011100 11 oss 0119 10 error orruissOon or negllOgence 01 ESC!, 11010 110/1100 11010 oletwork. secur011y OnSUrance (Toper coverage") 00'1/e0ing 05505 1105 0E) from a 0I00000)100 of conticlentiall 'information (nclluctOrng PH11) with cornbOnecl ao ggr e 11ll0lt 01$3 in 10.5. ESO'sAutornob011e ILliab011ay ncl Corn rn ercf allGenerallIGab011Ooty 05 1011009 poliMes 1100 10 conta Oro orbe 001000000 10 000111 On that they shal11111)e prOrn oy 'insurance 'Artro respect 10 1110 0o151001:1er. Any 'insurance, sellf- DocuSign Envelope ID: 6E11B861E8-3DIE8-41B21E-9649-C1F9869A63613 insurance or insurance pool coverage otaintainel by Customer shall ole excess of ESO's insurance aril sroalllInot 000U 00 with it. Onsurance is to lbe NL]000 with insurers with a current A.M.1Best rating of rootless than A VII. Contractor sit alllIffirnisit Customer with certificates of insuraince aril a copy Of the arciclitionallinsurect enclorsement or blanket aiciclitionall insurance enclorsement, evictencing the insurance requirements of ESO urnn executOon of trofs Agreement.. ESO shal111 hay e solle responsib011ity for cleterrnining the insurance coverage a ricillOrn its requOrect if any to lbe obtain ect ty subcontractors, which cleterot ination macie On a ccorciance witro reasonable ant prurientbusiness practices,. provicteci that ESO remains responsible for al 'work. performer:I lby any sulbcontractors. ESO shalIllprovOle Customer with written notice of any policy cancellation 'ocorOtroOn two business lays of their receiril of such notice. Fai ure on Hie part of 1E50 to in aiOnta in the insUral rice as requireci shal111 constitute a material breach 01 110 Agreement, upon 'which Customer may, after givOng five b 0 ness clays notice to ESO to correct the breach, immectiatelly terminate the Agreeir ient. or, 94. its clOscretion, procure or renew such 010 :00000 ant pay any ant all premiums in connection therewith with any SU ins 00 epopenctect 10 be repa icl to Customer on clerna not or atINC solle cliscretion 01 Cristorner, offset against furls clue ESO from Lootoorier 11 INDEMNIFICATION 11.1. Onclemnification. Subjectto the limitations in Section 12 1E50 shall clefencl inctemnity and hold INC Customerlroarrnless from any aril alo rio rtipies llosses ciamages costs liabilities, expenses (incll willing reasonable attorneys fees) for boctilly Onkiny, clam age to real property or intellectual property infringement FilDamage01) arising 01:1 01 or resulting from INC acts, errors or omissions of E50 in performance 011lroi's Agreement, arcept. for injuries aril clarnages causect try the nolle negligence of INC Cristomer Onclining brit not limitecr to a breach of unsecureci persona° information causecilby ESC) 00 its sulbcontractors or agents. Ffsither, ESC) shall inctemnity, crefenct ant toll the Customer Iroarraless from any Until -party claim or action alleging that the Software clelverect pursuant to tris Agreement infringe 00 misappropriate any thircl partys patent, copyright Pane secret, or other intellectual property rights enforceable in the applicable (1:0001 0109 (eacro, an nfringement Clairol. Of Customer makes an Onfoingernent Claim uncler this Section or if ESO cleterinines that an Onfringernent Claim may occur ESO shall at. its °Mori. (a) obtain a right for Customer to continue using such Software (b) moclify such Software to make it a non -infringing egi.fivallent. 00 (0) replace such Software with a non -infringing el. 1/9 lent. Of (a) (b), or (0) above are not reasonably practicable, either party may, at its option terminate INC relleva nt. Software Sore:tulle in which case E50 w rel :004 any pre-paillEees on a phorate lbasOs for such Software Schectulle. Irrotwithsta roiling the foregoing ESC) shall have no obligation Inereuricter for any clat m resulting or arising from (x) Customer's breach of this Agreement. (y) mocliiications macle to the Software that. were not pert ormect or provileci 11..00y or on lbeha Of of 1E50 or (z) the combination operation or uselLoy Customer (a ncl/or anyone acting on Cust.omer'slbehallf) of INC Software in connection with any other procluct or service (the combination or ipint use of which causes the allegel infrin(ement). This Section 11 states 000 solle obligation and liability and Customer 0 sole remely, for potential or actual Onfringement Should a court of competent jurisdiction determine that this Ageement is subject to RCW 4.24.115, then, in the event of liabilityfor damages arising out of bodilyinjury to persons or damages to property caused by or resulting from the concuirent negligence of ESO and Customer, its officers, officials, employees, and volluMeers, ESOiblliyhereunderhabeony to the extent ofESO negligence. It is further svecific ally and expressly understood that the indemnification provided herein constitutes ESO' s waiverof immunity under industrial Insurance, Title 51 RCW, solelyfor the purposes of this bidemnification. This waiver has been nnitually negotiated by the parties. The provisions of this Section 11 shall survive the expiration or termination of this Agreement. 11 2 OnlerrinificatiOn Proricerlures 'Upon lbecooning aware of any matter wN Otr s sub(ect to Be provisions of Sections 11 1 (a Lila io ri"), Custooner iriiSt go ve prooript written notice 01 such Oa io n to E50, accoonpaniel by copies of any 'written 4 ocuonentation rega rcl OlE {ERZ2238117.DOCX2/13175.000012/ the Cllaim recery ea.! lby the CUstomer Customers failure to notify ESO, and request indemnificaticpn shall not relieve ESO of any liability. that ESO might have, except to .the extent that such failure prejudices ESO' biUty to defend or compromise such claim or it. E50 shal111 compromise or clefend, at its own expense ant with its own counsel, any such Bairn. Customer will1111tave INC right at its option, to ['nit inflate in INC sett ernent or defense of any si.fcro Cllairn with its own counsel aril at its own expense: provOclect however that ESO Nave the rOgrot to control such settlement or (fief ense. ESO MOO not enter into a 111).e settlement tharoposea to011Oty or obligaVon on Customer withorit the Customer0 11'ior 'written consent. The part es wO1111 cooperate in any si.fcro settlement or clefense 000rl give each other 1::1111 access to al relevant information atIESO's expense. 12 LIMITATION OF LIABILITY 121 UMITATION OF DAMAGES INE11711•11EIP ES011101P CUSTOMER 5PALL BE ILIABLE TO 711i1E 0711.11ER 1F0R ADP COOISEQUEll TAIL 11111DIRECT SPECOAL PUINIITOVE OR 1 DE ITAL IDAIMADIES 1ILAIlk15 IFOR IDAIMADIES FOR LOST PROFITS DOODWILL USE OF MONEY, ITERRUPPEEI 01P IPA RED USE OF II ilE SOFTWARE AVAILABILITY OF DATA STOPPASE OF 'WORK OR IlkIPAIRMIEIIIT OF 0711 ilER ASSETS RELAT TO THIS ADREEIM Ell off 122 LIMITATION OF LIABILITY NOTIliTliElE4LEPT1101110 5EC71101111.2.3 (IL f LEPT11011(P Tu LOMOTA7110111 or ILIAIBILT) E5051N/A/NUM ADDREDATE LA LT ruIR ALL LILAIL°15 ulF LIABOILT ARI1511111D OUT Ur - OR 0111111EC P10111 NOTI11711 IIIS ADRILEMIEll 17 5111ALL EXCEEDTPE rErs PAID BY (uIP ull BIFII iAur or) 1iLl5T0lIVIER NI1711 ill I 711 ilL MEC EDI ITI1 PERIOD Ull IDER IIE APPLICABLE SuIFT NAPE 5111 ilEDULE OR SON V IB ROSE TO 711iE CILAIM 12 3 EXCEPTIONS TO LIMITATION OF LIABILITY, 11107WITII 'STA Ir IDIIIIIu 5ECTO0r4 12 2 (A) IBICEPT FOR1111'11DEN1111111FIICA71101110BILIIDA71101115 REILAT IG 70 ITELLECTUAL PROPERTY 111111FPOINGEMIErIT ESO 5 NABILITY' IFOR CLAIMS Ill NOLA° Itr ITS Ill IDE mr IIIBICA7110111 0BILODATI101145 Ull IDERSECTIlm11 SI ALL IDE LIMOTED 70 SE100 000 All4D (BIESO S LIABILITY 5'ALL IDE LIMITED TO T E AMOL111117 OFIIIIISURAI ICE COVERADE REcUll RED BY SECT11011110 IPORT olE FOLLOWIIII4u TYPES OF CILAIMS CILAIMS ARI1511111u FROM A REALP OF COPPIDErITIIALIITY 0BILIDA711011I5 11111CLIUDIIIIPB AS IDESCRIIIDED Or SECTI10114 13 ELOW 711rIERE 511r10 CAP 0111LIABILITY AR11511114u FROM Al 111111FIR1111 IDEMEHT CLAIIM 12 4 711.11E FORIED011111D LIMITA71101115 IE XCILL151101115 IDISCLAIMERS SI 'ALL APPLY REDARDLESS OF W ETPERT'E CLAIM flORSUCP DAIMADIES IDASEID (10 TRACT WARRAIray STRICT LIABILITY' 11'11EGILIIDEll ICE TORT OR 0711•11ERWISE °INSOFAR AS APPLICABLE LAW PROF ill BITS Al LIMITA7110111 HEREIIIIr ollE PAPTIIESADREE 711 olA7 SUCIli LOMOTA7110114 BALL IDE AUTOMATICALLY MODIFIED BUT ONLY TO 71111E 1EXTE1147 SO AS TO MAKE 711 ollE ILIMOTAT11011 I PERMOTTEID TO TO ollE FULLEST 1EXTEllif POSSIBLE UllIDER SUSI LAW TIE PART IIIES ADREE 7114AT 711.11E LIMITA71101115 SET FORTIli rIEREITI ARE ADREED ALLOCA7110111S OF RISK IPART 711.11E 10IN5OIDERATI10111FOIP 1E50 SOFTWARE All IID SERVOCES TO CIL1STOMER, AINID SUSI LIIMITA71101145 WILL APPLY 107WITIIi5TA1140111 711.11E FAILURE OF 711.11EIESSIEIIITIIAL PURPOSES OF ANY' UNITED REMIEDY All'olD EVE ° I OF A IPARTYlliA5 BEE114 ADVISED OF 711.11E ROSSOIBILTY OF SUCIli LIABILOTOES 12 Fro 711 illS 5LCTO I125lALL5UEVvE 1EXPORATOCIIIIOR TERM1111o1A7110114 OF 711.11E ADREEMIEIIIT 13 CUSTOMER DATA & PRIVACY 13 1 owrer$Iirop1 Data As lbetweenIESO arc! Customer o Cintooner IData sNi be own el by Cu ston leo 13.2. Use of Cristorner Data. 'Unless it receives Customer s 110 00' 'written consent, E30 shall not. (a) access, process, or otherwise use CrIstorn erlData arc! (b) intentOna Illy grant any thirciTa Otye 000ess to CrISIt. Din erlData , incliflOng wItroul iro lotion ESO's mbar crIstorners, except srfbcontractors that are sulroject. to a reasonablle nonctisclosure agreement or a uthorizel partOcipants in the case of Onteropera Software0tw01 trSIThrl OlE th e foregoing ESO irioy ‘Ise an cl 011'001100e Cost. Din erlData 10 11:1 lilts obligator 0 okricler this Agreement or as requirel by a pplicablellarw orlegao or governin eiOI'j oulloority. ESO shalIllgve LusIoiriCr prom ort notOce of any suchlegay governirlentall clemancl o'easonalrolly c000rierate vv CU stoiner in any effort to seek. o ofirotective miler or otherwise to contest such req‘.11irect clisclosure, at. Customer's expense. DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 13 3 Lorottfiyiraiintritt lDiotogoot CIUSTOIHI1ER ACKIrlOWILIEfitulES All ID Au300STIAT IOTWIITIIISTAII 11011110At 3 OTPES 33OVIS110111HERBSSOIMAY 'USE A111011M1112tEDIDATA FORIIIIITERII IAL AHD EXTERII IAL PURPOSES (11111CLUDOPlu BE° ICIIIIMARK1111IOAID RESEARCH), PROVIDED filiAT E50 'NOLL HOT SELL A111011N101117ED DATA TO TI ORD PART 05 FOR 000101030 AL USE Writ houtlInnnam g the toregoong, ESO wn1111 own all night, title a nit nnterest nn 11111Intelnectuall Property 01 any aggregated and /let dentirtned retrofits, summaries compilations, anallysns statistics or other nntormation derived theretronn 13 30 01 01.100 re CilsItorner cknowlledges and agrees that hosting data /1/0 000 risks 01 Inman utherizect /1 00 and that, lin 000000 /l anci insling 11:0 SaaS Cust.oiner assilines snich Psis. Customer has solle responsnbnlInIty tor obtannlng, malntalnlng na secinning Its /1010/0/1 connections. 13.5. E50 shall° inanntann 1.1 tal breach pllan nn accordance iwntlir the criteria 091 10/11: nn ESCris privacy and security '0 0]' and shall 1:111 0/110/11 the procedures requnrect nuncler sinch data breach pllan on the occurrence 01 a data breach, In comphance with the requirements of Washnnentonis data Ibrea ch notitncationllaw cocIntned at ROW /12.56.590. E50 shall report., In writing, 100ntry any data Ibrea ch 0000 /1 Cinstoiner Data nnollininfing any reasonable 00 01 that an unaintrrornzed ninclivnctuall liras accessed CinsItornerlData. The reportshall nclentity the nature 01 the event, a °list 01 100 afitected nnclivncli(alls and the types ot data and the in itngation nit ni/ estigation efforts 01 ESO. E50 shall make the report. to Customer nininecinatelly r'ort cfiscovery 01 100 data Ibrea ch but 1111 no event more than °five (5) ILAI ness days atter Cnscovery 01 100 data breach. E50 srrall provide nirvestogatoon ispolates to Customer. 13.6. E50 shall promptly reimburse Cust.orner tit° tor all costs /10 /1/0/1 py Customer In any nnvestngatnon reinethation or Ontngaltnon resitting trom any data breach. ESCis duty to reimburse Custorner /10 1/903 but ns not hunted to reninbursning to Cinstorner nits cost nincurreci In /10/13 11:0 following 13.6.1.1i1011n0011non to thnrci partneri 'whose 010011/11 0/1 may have been or were corrpromnsect and 10 /93 010/11' bocinesillaW- entorcernent agencnes or other entities as may be 31111/ /90 byllaw or contract,. 13.6.2.1EstablInshin3 and 1110111i10ri0g calIlloenter(s) and credit ontorn nig nctxor nclentity restoration 09/0 090 10 0100 01 each person ninfinacted 1]' /] data Ibrea ch 01 /1 /1011/1/0 111/11 lin Customerssolle cinscretnon coullcIlleaci to ncienfity theft anCi 13.6.3. Payment otIlegalltees anct expenses audit costs tnnes and pen al Ries, a 1111.1 Oth er tees nmposed upon 0/010/11 9/ 11]' 01 /93 /110/]' agency 00110 01 a W or contra otning partner /10 a real Ot 01 113 aata hreacItt. 13.7. 'Upon a data breach 050 ns not permitted to notify afitected nincinyncluallswnthout the express 'written consent ot Customer. 3' 900 E50 Is reclUnred roryllaw to provnrie 111 01ficaltion to thnrci partnes or the 0111 9019/1 nn a pa inticinllar manner, Customer shalllIcontroll the tnine, 111/1 09 an CI anner 01/011 notitncatOn FEEDBACK RIGHTS &WORK PRODUCT 14.1. IFeediback Rnifits. ESO does not agree to treat as confidential° any IFeerlbackthat Customer provncies to E50. Nothing lin th 1.10 Agreement win restrict ESCris right to use, 9/011 1/0/11 /1 00000 fiublInsh, keep secret or 01119/3 09 eifillontlFeectback 0/1110 /1 compensation or crediting Customer. IFeeriba 01i0/n1111 /101 constitute Contnclentiall Ontortnati even It lit won.111/1 otherwnse quallnly as 01.1011 finirsilaint to Section 9 (Confirlentnall °Wort/ration). 14.2- ActIlltiaEllatlitcliQAIltratgttill.11fi the event. Custtoinerlihires 050 10 perform ProtessnonallServnces 650011one sltallIllkoll0 btlle, nci interest to all proprietany ancl /119 9011/0 property oinghts 01 109 Delliverablles (/10 /11 without IlinUtation patents trade secrets, coryytights, anci trademar)s), as well astifile to rry copy ot 00110/11/9 :10190 by 0/ 10/ Cinstorner applIncablle). Customer hereby explIncntly acknowlledges and agrees that nothing in 1000 Agreement 0/ 01 separate SOW 3090 109 01/010/119/ 01/1]' rlght title, or nnterest. Ito the /119 901 property or fitoprnet.allY know-tnow 0111:0 Delliverablles. 15 GOVERNMENT PROVISIONS 15.1. Ciogurrouritilignage.rwirtiolottArwa. 13otrr parties sin alllIcom pty with and give 101111 n01 090 regin(nred by alIllapplicablletederall, state 0 ndllocallllaws, (ERZ2238117DOCX,2/13175 000012/ ) ortinna n Ces /1/ 90 re8ulla1°0111 0 a 1110 0 al U Or aers ot any p ‘1 b 0 10 al fixity bearing on se 01 109 .5ottware and the perfortrrance ot thIs Agreement 15..2.. Reserved. 15.3.. lEc Ouriortunnt x. The 11/1/190 010] abide 11]' 113 rectunreinents at 41. CFR 60-1..4(a ). 60-300..5(a) and 60-7/11..5(0]),. and the posting rectunrernents 01 29 CIM Pa0. oir171,. appendix A to subpart A,. or 011111 001112 These /931/ 0110/10 prohniont chscolinnnatnon against qualairiect /1/1 '0/1/0] 1101se0 on their status as protected 'veterans or nroctivnclualls 'with Oisallabbes,. anci prohibit. /100/0: /10110/1 against all /1/1/1/11 /010 lbasect on their race00 0/ /9 30/1 sex. sexual orient.ation. 3en0er icientity or naltnonallorIgn.. 15.4° 1EXcllu090 001/1es.0iis1..1E50 agrees Ito nininechatelly report. to Cusltoiner an emplloyee or contractor Is °listed Itty 1e0er0ll agency as debarred, ex0ll1/090 or otheownse nnelIngiblle for paint cnpation nn terierally funded health care programs.. 1/0 AOCURACY& COMPLETENESS 16.1. 650 provides the Sottware to allow Custorner (10/1/1 Its respecfive 'Users) to enter document and chsclese Customer Data anuti as such, E50 gives 1110 r 9I '/939/11011 es nta non 0 or guarantees about the accuracy or 00/11/1 919/1900 ot Customer Data entered niplload el or cinscllosect through the Software try Cinstorner. E50 agrees that It win not alter any Cust.orner Data. 16.2. 0. /010/110/ ns sollelly resporosnble for any decnsnons or actions taken /1/0/ /13 patient care or patnent care management 'whether those decnsnons or actions were made or tak.en ‘1Sling nntormation received trrougrr tre Sottwa re. 17 MISCELLANEOUS 17 1 MrJelaerMent Contranctrons The 1110/1 90 are independent contractors 19 tlr9r °ratty os the agent 01102 other and neither /1 10]]' nria) conrinniltnr rents 0111 the other s behallt The °ratites Lier ee tIrolt 1110 ESO 2111° 100090 or 00/11/01010/ os or voill be 00/10 /19/9/1 an 9000099 01 CusitonrIer 17.2. li101 090. 0"',101.100 0 provncterl uncle/ thn's Agreement inn/s1 tie In iwoirtning and delivered by (a) cerfitned man° return receipt requester( to a party's principal° pkice of busnness as tooth In INC recitalls on page 1 of this Agreement (b) Intim"( '19 1/9/9/1 (0) tacsninte receipt ot "Tran0inn00.110111 Confirmed acknowedgment, (d) e-trituill 10 0] person clesngnatect nn writing by the recenvning party, or (0) delivery 11]'O] 9I 1/10111 overnight 0O]// 9/ 09/'! 09 On the case ot delivery 11]'101001i01te or 9/no] the notice must be °followed: 110 0] 01)110 01 INC notice being deliverer! 11]'O] means provncie(1 nin, (a), (11) 0/ (9) The /101 O9W be deemed: given on the day the notnce Is recenvect. 17..3. 1M er.oier Clause. entering nnto Ithns Agreement nenther party Is refining Upon any representat Ons or statements ot the other that are not °hilly expressed nn thnsAgreernento rather each tiarty Is relying on Its 0,0/111 Judgment and clue chlIngence and expresslly chscllanins rehance upon a rry representations or staterr ient. not expresslly set torth nn thns Agreement. In INC event the Customer nissines a purchase order, Ileitter 0/ 01/1]' other /100 /1 ci dressning the Software or Setynces to be urrovOcteci and unentorrneci pursuant 10 this Agreement It nsIrreireby specitncallOy 01gree/1 J/1(1 ‘.1111 cterstooa that any al Ch 'writin g ns tor the Customers Internall Purrioses erollyi and that any tennis, provnslions, and conditions contannect therenn shalllInn no way modify th8 Agreement.. 17 Seyeroorlpillitty. To the extent perrnnIttect by a prol001t1llellaw, the pa rtnes lioereby waive a/1]'l'0y sliorrt 01 aW WOU /1 /9/1/19/ any 0O1 /0901 thIs Agreement /1/01 /1 or ollteromise ‘1rien10r0e0]ltile In any respect. It a tirovOslion of this Agreement. Is belt( to tie nrovallnd or 09V 09 unentorceablle, such provnsnon 'win be nnterpretect to tultnInntntended pufitese to the maximum extent pertnnIttel by applIncablle Daiwa and the rein a nionng provnsnons 01 this Agreement 'win continue nn tit° torce and elect. 17.5. Sulticontractnny.lEXceplt tor trannnrog and nintilleinentatnon 02/0 090 /91119/1 10 the Sottware nenther party may silbcontract or clellegate Its oblIngatnons to each otherlirereithrter, nor may °100/11/1001 wlth trIlra 110]/1 to perform any 01 its oblIngationslinereuncler except as conternpllatect nn tros Agreement 'without the other oiatlys prior written consent. 1.7.13.INilorlotocations and Amendments This Agoenennent may /101 19 annended eicett tiro plug)! a molter 'tier eennent sognerl autlUorrizel DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 representattses of each panty provOclect that. the Custorn er agrees that E(50 may rally on 'informal writings (iincilluclOn( ercia(110) of Customer's alutrionizec) representat ves to (I) terminate Software prori(icits url semices anti (ii) approve or ratify rate ooi tier 'increases for Software proctrocts a mil services then On use by Customer. 17.7. [21ciglMgigloolfcl roio rie ov farillure, or clefaullt w const 1 :te reach of thOs.Agreercient 10 100 extent canisect by acts of owar, terror Sir hurricanes, ea OM qua lies, other acts of Clocl or 01 nature, strikes or other °aba 0 sOlItes r ots or other acts of cOvOlIcrisorler errnbargoes, or other causes beyond the performing party's reasonablle controll (co011ectioselly ilForcelMa)einieF). On such event, however, the cl ellayect party must prorrflort.11y proosOcle the other panty notice ()tithe 1Force Maieure. The clellayeci (ortV 01 uie 10? pentorrnance MI be eircusect for the critatOon of the IForcelMaierebut Of the event Oast llonger than 30 clays, the other panty may OrrutecriatellyteroMnate the appllOciablle Software Schectulle. 17 8 Ii,]8 01 o 1 reoplestel bylE50 CustOir ier aEoees to oeasonablly cooperate with 1E50.1's o)repaoatoon incl issuance 01 u) 0 announcen lent oegaolonE the rellationshoo) 01 the ofaotoes 17 9 Woiver & D ea oh 0 tirer ao toy won beleernel tolirove wa overt any rogirts (Inler this AEo eeonent ot os n eMloat wootten waver ocr male by an auth000zecl repo esentatose lilo Wal ocr 01 a Itn each 01 this Ago eernent w constitute ai WO ocr 01 any 01lireolboeachlireeo1 17 10 5urvosa1101 Teo rris Uo eso otheowise stailel all° 011E500 aril Custoonet s respective 0) )o1 0115o, ern esentatoons and wao o [Mies (incleo ithos Agoeeonent which are not by the eiipoessel tie" ons 01 ithos Agoeernent lu to be pentournect wholle Mos AEmement os on ellecit shall survive the teornonatoon 01 Mos AEoeeor lent 17 11 Aoribo j.,(10(is Teo ((Is This AEo eement won not be constru el against any o)aoity by rea son 01 its rioepaoatooro 17 12 bovernong Law This Ago eeonent, any cillaion lospuite or controver sy Ineoeuncleo (a 'Dispute) won be goveon el by ( (INCllaws 01 INc State 01 WashonEton The panties specot calIlly (inleo staff! and aleteetlirat venue shall° toe poopeolly °ori on InioinE County "NashonEton INC COnventoon1oo thelliorteo oi ;Lotion allSa Ile 01 boors a n1 INC lUnoitoo on Loripuler rntonor ',Lotion To ansactoons Acit W 001 applly On 0107 Dispute ea clir pa rolty mIllIbeao its own attooneys lees a rol coats a rol eiipoesslly waives any stat(itooy roghtlt0 attorneys Tees Ontentoonalllly Ornottecl fil°21(111°21(1:41111l(10flOnEilit. Ontentocro alIlly Oon ottecl (ERZ2238117 DOCX, 2/13175 000012/ ) 17.16. (DoliogniitLiBigggiltil(coiri. Cit.,storner a n d 1E50 W(110 a tterript 10 resollose any 03) :01 through negotiaton or by utill(0(ng a met ator agreed 10 01 the part (es, rather than througroll(tigation. Negotrat(ons and inert w(11111be treat.ed as confidentiall. Ilf the part es are imalblle t.o reach a resollution wil.h(n 30 days 01 not(ce of the Dispilte to the other party, the (0 7)95 may pursue an other courses 01 a °ton avanablle at Ilaw or (n equ(ty. 17 17 00(70.0.1Illri TIE895 1111U T11E1E21E11\11 OF A C011,1FLOCTIDIETWIEE111( THIE TIMMS OF TH1E COr000lTRACTIFOIRSIERVIICIES, TO WHICH T0O5IE0.10111811T 7)57)117)000.0 TIHIE TIERIMS Arun(' OT11-11EI8I000UMIE111\11 (11INCILUIDIllf(1101T11101LIIHIIITIED TO, T1111151E71011181IT A OID ANN OTHIER lEIMIIBIIT TO THIE C011oilTRACTIFOR SEM/10E5)1HE TIE91115 OF THE' COIrITRA.CT IFOR 51EIRVIICIE5 SH.A.LL 0802A 0. 17 18 Icolrrro oy Ec)orl Customer shall° not (a) peo (not any thoocl (01710 access or use the Soittwaoe on soollatoon 01 any U 5 Ilaw or regullation, or (11i) e<i)orlt any SOlitWal re prov ri ecl ii 0.50 or otlirerwose reor love ot oon the Uoo tel States e <cept rr con 1phance oivoith J appllocablle U 5 U.S. and oeEfillations Withouthornitong the generality oil the Tooegoong, O Istoorier shall° not perori any Hurl party to access or use the Sotwaoe on, oo eioporolt such sort wan e 10 a country sulbiect to 0 Unotel States eorilliaoE0 (as 01 th elEhtectovelDate - Cuba Doan(oo 1Korea Sulan and Syria) 17 19 20or (21 Ercgcclgligg tical 01 any 00(1111001 l)etween tliros Ag,oeernent AcI1enla or other attachments oncoopooatellireo eon toe 101100°14(1E rrN fie o)oecelence wolIllgovern (1) the 0 001trcoI tor Services with its attachel eitobots , (3) the 008 Sortoivare Schelulle or SOW with (-roost recent Sortwaoe Schelulle or SOW tallionE prcocricrroo over ea o Ilier ones o00 (nil) an Y ESO P 07 )0100) onllone ono:holing without °on ntatoon its prosacy pollocy no an ienclor lents oncoopooatel onto tiros Agmen lent alter e'ioeciition 01110/ laeineo all Teo ((is and Lorrci I0015w annen1 such L,eineo all Teo ons cold Concloto ons (lioness 1 5)901 00 states oits intent 101000 and cotes the section or sections aoneoll el 17 20 Colionterpants Tliros AEreeo (lent ((lay toe ecec(otel on one or oriooe 00(1nteo pa oolts lEach counteo pa oolt 0/ 10/ an on Ei in all and alllIsuclir 00(onteo pai rots won constitute a single instrriLiiinernit 17 21 So Matures lEllectoonoc aEnatures on thos Ago eeonent or on any Aci0en1(lon (or copies 01 a(7natuo es sent so ellecto priori on eans) 000 the e(1(1o001lle11101111a in clwo otten signatures D o co Si g n Envelope ID: 6E 11B86IE 8-3DIE8-41B21E-9549-CIF 9859A 53513 IN WITNESS WHEREOF,. the parthes Ihhave ehhh.ecultea thhs Agreement as hthl the lEffectrve IDate LSO Solutions, Inc. Doc uS gned by: Customer Cityoflukwila W shington Ilitztit Maw By: By: AgE931CMTEzrrc,-: (sig nature) (signature) Matt Walker IJ rn (print name) Na rrh e: (print name) COO itlo:Title: (print title) ( {ERZ2238117000X,2/13175 000012/ } DocuSign Envelope ID: 6E11B861E8-3DIE8-41B21E-9549-CIF9859A53513 flITA- SAASAS SOFTWARE SCHEDULE (Applications - ESO EHR. ESO Fire. ESO PM FIREHOUSE Cloud. IFC Codes. EMS1 Academy. FireRescue1 Academy. StaffScheduling. Assets. Inventory. Checklist) 1.. The SaaS sulescrefotion tern) shall° Inegin 15 callenclar days after the lEffectiore Date biSaaS SulescreiiiitOort Start Date:). Custorcier shall° be deerned to il/:ye accepted the Saa5 on the SaaS SubscrOption Start Date.. The part es w obak.e reasonablle efforts to ensure that Custorner Os ablle to use the 5aa5 is conterrkellated as ()trickily as ofiossiblle, limit On no event well the SaaSSulescrikotion StartIDate be rnoctOkied for Ornielernentabon dellays.. 2 The to:II:won SaaS on ay be ordered oin ler thos LuO 31 2..1.. 050 Perscnne tIur6errient. t(PkiE) Os a SuuS software a ppllication tor tracking personnell recordstraOnOng coierses and education hOstory 22.. ESO Are Os a SaaS software applecation foriiirAIRS reporting fiiitifirikijkiewkiiiiiiiciiirceirkiiiiiiiiititrikrionibrifir0).. 3 Preto:lowing Thool-Party Data ancl/oo Sortwaoe on/1y be orlerel uncle: this 1E(lieliort 2018 nteo national° Fore Cole 2015 Onteo national° Are Cole 2012 nteo national° Fore Cole, Eloicatoon (see section 3 5') Thorcl-PaotF0ier s oesponsoliolle lor the 10111lowon et products a oil Fees IN/A 0 toorier ireoeby ago ees 101oonelly pay lor the following pooloicts according to the schecloille bellow Are , [30 Fire Incidents Fire Incidents NFIRS Data Impert Telestafir Integration Fire Incidents 0010 Integration Fire Setup & Online Training 4 Stations 5083 lint; idenits 5083 Incidents 5083 Incidents 3 Sessions 14,200 00 13,995 00 $1,695 00 12495.00 $1,785 00 14,200.00 Recurring $3,995.00 One-time $1,695.00 Recurring $0.00 Recurring 11,485.00 One-time Asset Managementfinventory , Asset Management and CheCkIlist - Training and 15 Venides implementation Assets -Checklist Bundie 15 vehiCies 6.. Alll the Fees above well be 0/0 000 by ESO as follows, 6..1.. 161 liming and Tru renTravell IFees shall° be Oro/Diced on the Effective IDate.. {ERZ223811 7 DOCX,2/1317.5 000012/ } $1,495 00 $3,495 00 $0.00 $0.00 $1,495.00 One-time $3,495.00 Recurring Total ROC! urring $ 11,965 00 TOtall One -Time $ 7,275.00 Discounts $ 2, 795 0(1) TOTAL $ 16,445.00 DocuSign Envelope ID: 6E118861E8-3DE8-41821E-9549-CIF9859A53513 6..2.. During the first year,. 100% of the remaining Fees sllha 110 be invoiced on the Sa aS StMscription Start Date.. 63. Dialling the second year a] nd irry renewa wars thereafter, 1005 of the recuning Fees shall lhe due on the al nni'versa [rye of the 5aa5 Subscnifbh on Start Date. {ERZ2238117 DOCX,2/13175 000012/ } DocuSign Envelope ID: 6E11B861E8-3DIE8-41B21E-9549-CIF9859A53513 111 A-2 4..DD I Li DEFINITIONS Capotallozel teorns not leronel bellow shall ltrove the saone oneanone as on the Lieneoall Teorns & Cora:lotions 1.1. ilEnha [ricer)) &it' means a mollification aillOition or new release of the Software that 'when a Oriel 10 160 Softwo re, Riot erlially changes Oits eff ci en cy liorol orw 0 ao pa b OIV or ap pll O o'jl Dir 1 1.2. '1Ernifll Suptiort" means abillity to make requests for technOcall support. aissOstonce by e-iroi i1 irily bine concerming the use of the then -current release of Software. 1 3 "lErrIr orr onea ins an error on the Sortwooe which soen or ocartly leEoo ales peoloornan ce or such Sortwooe is compaoel to 1E50'0 then -publisher! Doctiorient at ion 1 niol 'Lrmr Correctiononeans the use or oeosonable coorioneocoall 01106010 correct Errors 15 7 1 ir 303 113 the repo or or replaceorient ot object cole tor the Software or IDocuonentatoon to reonedy an lError 1 6 Anita° Response' oneans the roost contact by a Support Repo esentatove alter the oncolent liras been loeeerl aril a ticket eeneo oiler! This onoy onclule an autoonatel email response leienlong on when the 110 60111 os roost cooriontinocotel 1 7 IManaeeonent lEsca lotion" means or the initial Woolt000unl or Rin1110es not oesolve the lEoroo, noltorocotoon 011 rriorni(eirierr1 that s1:c0 lError(s Ira) e been rep anr! 01 steps being tallien 10 00111001 such E000ls) 1.8. 'Severity 1 Erro( means an lErr or iwrilich rerniers the Software completely 'inoperative /0(0 User user cannot alccess the Software clue to un sch eci to II el lownitime or 30 Outage). 1.9. 'Severity 2 lErr or' ir 03113 n Error On 'MI C h Software Os 31 pera blle rowever, one or more slip ITO a not f eat to res or f ‘.1 n rib on a II Olty are 1.1111 al V alilloblle (e.g., a User cannot 3000003 core component of the Software). 1.1. 'Severity 3 lError' means any other error that cloes root prevent a User from 300000 OE( 11 03111 feature 01 100 Software (0.g, User Os experiencing latency On reports) 1 2 'Seventy n1 lEn° or' or leans any error relater! to IDocuon en ation ar 6 sloirier Err iranceonent request 1 3 'Status IUplate' oneons T the initial Wortoomincl 011 A! cannot oesolve the Error notorocotoon or the 3 S10irier oegoolonE the pooepess or the Woo II ,a ounr! or A! 1 4 "Online Suppool" means onroornation available through ESO's websote (0/ivy 1 nclulong 0331 a slier! questions a roll bug o epoo tome, voai Love Cloroalt 1 5 Support Repo esentotove shall be E50 eoriployee(s) oo algeonot(s) rot esognaltel to oeceove lError 11101011031101110 boon Custooneo which Custooneo's Al mo n slr3lor ras lteen un able to o esollye 1.6. ilUpoate" means an i(I111k110 or revOslion to Software, typOcollYf or lError Correction 1 7 1Upgr3le means a new version or release or Sortware or a partocullair component or Sortwore, 'which oonproves the tunctionalloity or 'which arils runctionoll capabilities to the Sortware 3rrrt s not onclu lerl on on Uplate IUperoles onay 110 1:1110 lEnhanceonents 1.8. Wortia mural" means a change On the procelures follower! or 0313 supplIO erl 106lsitorner ito avolil a! in lError thout substantially 'impairing Ctost.orner's use or theSort.wore. 2 SUPPORT SERVICES. 2 1 Custooneo poovole 31 east one alononositraltove eonployee (the "Alononositoatoo ' or Airl rr s1r31ors 1 who won lirarable 3 requests lor bost-levell stippoot boon Custooner's eonplovees woth oespecit to the Sortwao e Stich stippoot os intern -10110 be the "bon1 lone' roo suppoot 311111 nr000notoon about the technical supporr it Custoonebs Users The Alononostootoo m1111 notify a Suptoot Repoesentatove or any lEo 000 s hat the Arlon° n sito atoo cannot oesollye irrci Sortwoo e to Custooneo's Users ES0 poovole itraonone locuonentatoon 311111 onateo pills to the Arlon° n sito a to o to enable the Arlon° n stra too to poovole assist 750 on nroom alto On gailler one geoleorailloyo available to its custooneos without ailloitionoll charge, aril (0) Suppoot, telephone support, alial Online Support ES0 onay use onullitople 2 2 E50 m1111 pmvole Stiptert Services consositone or (a) lE0000 Con° ection(s), lEnluanceonents, IUplates ainr! Upeo ales that ESC), on its loscoetion makes rooms or coonmunocatiOn Tor puo poses 01 subonottone perooloc status reports 10 Distooneo inch:clone but not loonotel to onessoees the Sonowaioe , („h1 {ERZ2238117 DOCX;2/13175 000012/ } T71 'OD DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 messages air:meaning upon Iloglin to tInet Software or other ineans c4 brow -toasting Status Upciate(s) to inullintille customers rroffectect by the same IError, such as a customer portal 2.3. ESO's support clest.willte stiffer Moth competent. technOca consullta rots who are tralinect On a inct thoroughly farocilliar wOth tIne Software aonct wOth Cust.orneris applicablle configtoraton. Tellephone stopport atoll cornothorticatO or: wild be 3e '/erect Oro OntellOgiblle English. 2 4 floo rot all boo sooi ess trourstor E30s supodoot eest are Nionlay trio ougt Frio -A ay 7 00 a rn to 7 00 pori LT Li:stcrer w oeceove call back to 0o n a Support Repoesentatove atteolnoolos Tcr Seventy 1 lErootio 3 ERROR PRIORITY LEVELS. Coostooner m1111 report all Errorsto E50 viva e-onaoll (Linn; lind iinity toxic) or lby tellephone (866-766-9471 opton 43) E50 stall eriercose coononercoally rea son a blle ettorts to correct any lError repootect lby Customer on a ccon/an ce mtt e prooroty Ilevell reason albly assigned to sooct lError by 030 3 1 ,ararottyLE.Ecot ESO shall Ol) commence lError Correct on promptly; (On fro/ cte an On Olia IResponse wrtlrOr totor hours, (OOO) On it Orate 3lunuEerrlerrt lEscallation prompty, and (Ow) provO0e Customer with a Stutrrs 'Update Mtn On tour Irorrrs Ort 330 cannot resorve the Error 'Nat On tour Irours 3.2. 5ey ernt e 2 Error. E30 shal111 (0) commence IError Correction prointiiitilyo (On provOcte an 11nOtO all Response vornit.lrolin eight Itioursi Olin jinni ate IManagernent lEscallation wothiin 48 hours nt ‘.1111 re sollvecto amort (Ov) provOcie Custorner with a Status IUpctate ioirytt.111Oro orty-elight hours it ESO cannot resollvetlitelError wothiin fortyreOgrot foours. 33 Severity 3 Error E50 st (o) coo n o nen ce Error Correction p000nohtlly, (oo) o)oovocle an On otoa IRespon se million trooee Ithu son ess days, aril (000) I0 0l9 Cirstorrier wott a Status 'UN -late wott on seven ca eorloir rlois 1 E50 cannot oesollve the Error within seven ca erroloir clays 3..4.. Sev Prnty 4 Error.. ESO shal111 (0) prcyoole an n 1 Response withOn seven callen0ar clays.. CONSULTING SERVICES. Of E50 reasonalnly believes that a 000 901 retiortect Iny Customer Os root clue to an Error On the Software, ESO wild so not ty Customer. At. that tine, Customer may request ESO to proceect 'Mtn a root cause anallysts at 6 storier 5 expense as set forth Inerelin or On a separate SOW. Of 630 agrees to perform the Orivestgation on Inehallf of Customer, then ESCiis then -current. ancl sta ncla root consulting rates MO pplly tor all 'work 1 e000rrierl n coninection Miro such anallysis, pllus reasonablle rellated expenses Oncurrect. For the avolicia ince 01 010011 Con sulliting ServOces w nollucle o stornilzect retch( iwrilt.Ong Ihy E30 on Inert ant of CUstorner. 5 EXCLUSIONS. E30 sria1111 Inave no 01011Og5tion to perform Error Corrections or otherwise promicie support 100 (0) Lustorier 5 0030 OS ma Oritena nce or modthications to the Software (Of perm Ottect) bin Customer's rotisappllOcatOon 00 ‘.1nauthoodzed tose of the Software(lin Otered 00 damaged Software not CaP.Isect ly E50,, (Ov) any thOrclidarty software (v) 111 archival re Osores o (vO) Customer's nreach of the Agreern ento anti (oniO) any other causes Ineyonct the 1ESO's reasonablle control 5 2 E50 sIrs n aye 00 ha bollo ty tor any Oranges on Cu storn eo' s Inaolwaoe or sottwaoe systeons itt at o nay Itoe rolecessaoy to oo se tro e Sottwaoe clue to a Woo 100 u nr1 00 Fo 5 3 ESO os not moo oi inert to pennon:1 any Error Correctoon unlless E50 can rep cute such Error on ots own sottwaoe and Ina clwa e or tto Quern oeonote access to 1 ustoirier s sort wao e and 111aoclwaoe 5.4. alstoiner Os sollelly responsObIle for Olts sellection of 111a rclwa re, and 1E50 shall not be responsnthe the performance of such 111a raware even Olt E50 makes recorninenclaitions regarcting the same. 6 MISCELLANEOUS The parties sol o 0wIledge that trona time -to -time ESO may update pts supplant processes specancaby addressed nn MIS lExhiba anct army rIo so Irry posting suon upriates to E50 5 websnte or otherwise notayiing Customer of such updates Customer m1111 accept updates to E50 5 sninflort procedures and any other tern's nn thns Exhibt, proyncied however that they do not maternallly decrease Hoe Ilevell ot Support Servoces that Coostooner m011receove troon ESO TlE3ETERCISAOC, C01101710115 DO 1110T COOISTIITIUTE A PRODUCT WAIRRAII1TY TIS 311 OT 11S All 1 ADDIT11011 iIAC PART OPTIE ADREEIMEll IT All „ID DOES 1010T CIA 15600 SUPERSEDE All a TERM OF T1101E ADREEIVIEllaT 1EXCEPT TO T1101E 1EXTEllaT IL1111AIMIDIDUOIUSILY C0101TRARY T1101EIRETO {ERZ2238117 DOCX,2/13175 000012/ } moousgmEnvelope ID: mE118mo1Eoaao^ana1n EXHIBIT B SERVICE LEVEL AGREEMENT (SLA) Service Level Agreement: The Sepvicem, in a production emvinonment, are provided with the service levels described in this Exhibit B. SLAs are only applicable to production environments. Actual Application Availability % = (Monthly Minutes (MM) minus Total Minutes Not Available (TM)) multiplied by 100) and divided by Monthly Minutes (MM), but not including Excluded Events. Outage Calculation(s): An Outage will be deemed to commence when the Applications are unavailable. Failure to meet the 99.75% Application Availability SLA, other than for reasons due to an Excluded Event, will be taken into consideration by ESO in the event Customer requests a good -faith discussion regarding the application of discounts to upcoming renewal terms. Customer shall track and calculate the actual application availability on a quarterly basis and shall notify ESO within thirty (30) days of the end of the quarter ifthe Application Availability is less than 99.75% triggering the discussions for discounts related to the renewal terms. Actual Application Availability % (as measured in a calendar month) Annual Outage Discount Calculation Rate <99.75% to 98.75% 1096 <98.75% to 98.25% 1596 <98.25% to 97.75% 25% <97.75 to 98.7696 35% <98.76 50% "Outage" means the accumulated time, measured in minutes, during which Customer is unable to access the Applications for reasons other than an Excluded Event. "Excluded Event" means any event that results in an Outage and is caused by (a) the acts or omissions of Customer, its employees, customers, contractors or agents; (b) the failure or malfunction of equipment, applications or systems not owned or controlled by ESO, including without limitation Customer Content, failures or malfunctions resulting from circuits provided by Customer, any inconsistencies or changes in the environment; (c) Force Majeure events; (d) expecteddowntime during established and agreed upon ESO Maintenance Periods described below; (e) the unavailability of required Customer permonne|, including as a result of failure to provide ESO with accurate, current contact information; or (f) using an Application in a manner inconsistent with the Documentation for such Application. "Maintenance Period" means scheduled maintenance periods established by ESO to maintain and update services, when downtime may be necessary, as described belowThe Maintenance Periods must be agreed tobythe CityofTukwilato be included in excluded events ampart ofavailability calculations. ilEm2233027.1DOCX; 2/13175.000012/ ) moousgmEnvelope ID: mE118mo1Eoaao^ana1n Customer Specific Maintenance Period 1. Customer Specific Maintenance will occur every two weeks on Tuesday between 12am and 6am Central Standard Time. 2. Excluding any customer requested Application updates, ESO will provide notice for planned downtime via an email notice to the primary Customer contacat least seven days in advance of any known downtime so planning can be facilitated by Customer. 3. Customer Specific Maintenance VNndowvm also include additional maintenance windows mutually agreed upon by Customer and Service Provider. Non -Customer Specific Maintenance Period If for any reason non -Customer Specific Maintenance requires downtime, Service Provider will provide as much notice as reasonably possible of the expected window in which this will occur. Downtime in excess of three hours per month for Non -Customer Specific Maintenance will be deemed to be an Outage. "Monthly Minutes (MM)" means the total time, measured in minudee, of a calendar month commencing at 12:00 am of the first day of such calendar month and ending at 11:59 pm of the last day of such calendar month. "Total Minutes Not Available (TM)'Means the total number of minutes during the calendar that the Service are unavailable as the result of an Outage. Reporting and Claims Process: An Outage Calculation will not be provided if the Outage results from an Excluded Event. ESO and Customer will account for Outage Calculations inthe event Customer during negotiations for the renewal of the Contract For Services. ilEm2233027.1DOCX; 2/13175.000012/ ) moousgmEnvelope ID: mE11Bmo1Eoaao^ana1n Exhibit C Data Protection and Information Security This Data Protection and Information Security Exhibit ("Exhibit") is an attachment to the Agreement and sets forth the data protection and information security requirements of City of Tukwila. This Exhibit includes by referencethe terms and conditions of the Agreement. Throughout the term mfthe Agreement and for aslong as ESO controls, possesses, stores, transmits, or processes Confidential Information as part of the Services provided to City of Tukwila, ESO will comply with the requirements set forth in this Exhibit. ESO shall provide to the CITY OF TUKWILA, upon CITY OF TUKWILA's reasonable request, but no more frequently than once per annum, and for no additional charge to CITY OF TUKWILA, a report which includes the results of its most recent SOC 2 Type || audit addressing ESO's security practices. ESO shall follow industry standard security measures as established and outlined under the HIPAA Security Rule. 1. Definitions "Authorized Personnel" for the purposes of this Exhibit, means ESO's employees or subcontractors who: (i) have a need to receive or access Confidential Information or Personal Information to enable ESO to perform its obligations under the Agreement; and (ii) are bound in writing with ESO by confidentiality obligations sufficient for the protection of Confidential Information and Personal Information in accordance with the terms and conditions set forth in the Agreement and this Exhibit. "Common Software Vulnerabilities" (CSV) are application defects and errors that are commonly exploited in software. ESO shall manage vulnerabilities as outlined in the ESO Information Security Policy Section 33 'Vulnerability Management", which is attached to the Contract for Services as Exhibit D. "Confidential Information," shall be defined as that term is used in Exhibit A. "Industry Standards" mean generally recognized industry standards, best pnarLicem, and benchmarks, for (a) National Institute for Standards and Technology — see httplicsrc.nistqovi (b) ISO /|EC27DDD-sehes—see (c) COB|T5—httpfhw&mv.|saca.orq/cob|ti (d) Cyber Security Framework — see qcvyc (e) C|oudSecurityA||iance—meehttpe://c|oudsecu,ityaUiance.org/ (f) Other standards applicable to the services provided by ESO to CITY OF TUKVVILA "Information Protection Laws" mean all |oca|, otate, federal and international |avvm, mbandardm, guideAinem, pcliciem, regulations and procedures applicable to ESO or City of Tukwila pertaining to data security, confidentiality, privacy, and breach notification. "Personal Information" also known as Personally Identifiable Information (PU), is information of CITY OF TUKVVILA customers, employees and subcontractors or their devices collected through a service provided by ESO that can be used on its own or combined with other information under ESO control or management to idenUfy, contact, or locate a permon, or to identify an individual or his or her device in context. Examples of Personal Information include name, social security number or national identifier, biometric records, driver's license number, device identifier, IP address, MAC addreem, either alone or when combined with other personal or identifying information which is linked or Iinkable to a specific individual or device, such as date ilEm2233027.1DOCX; 2/13175.000012/ ) moousgmEnvelope ID: mE11Bmo1Eoaao^ana1n and place of birth, mother's maiden name, etc. Personal Information might also be defined under applicable state or federal law in the event of a Security Incident. "Protected Health Information" or "PHI" shall have the meaning set forth in HIPAA. All references herein to PHI shall be construed to include electronic PHI, or ePH I, as that term is defined by HIPAA. "Security Incident" is any attempted or successful unauthorized accemm, use, dimdomune, modificaUon, or destruction of THE CITY OF TUKVVILA'm PHI or interference with ESO's system operations in ESO's information systems ("Security Incident" as defined by 45 C.F.R. § 164.304), of which ESO becomes aware. "Security Vulnerability" is an app|icaUon, operating mystem, or system flaw (including but not limited to associated process, computer, device, network, or software weakness) that can be exploited resulting in a Security Incident. 2. Roles ofthe Parties and Compliancewithlnformation Protection Laws As between THE CITY OF TUKWLA and ESO, THE CITY OF TUKWLA shall be the principal and ESO shall be its agent with respecto the collection, use, processing and disclosure of all Confidential Information. The Parties shall comply with their respective obligations as the principal (e.g., data owner/controller/covered entity) and agent (e.g., data processor/business associate/trading partner) under all Information Protection Laws. The Parties acknowledge that, with respect to all Confidential Information processed by ESO for the purpose of providing the Services under this Agreement: (a) ESO shall limit its access to or use of Confidential Information to that which is necessary to provide the Services, com ply with applicable laws, or as otherwise directed by THE CITY OF TUKWILA; (b) Each party shall be responsible for compliance with Information Protection Laws in accordance with their respective roles. 3. General Security Requirements ESO shall take at least indumtry-mbandard, nsamonab|e, and prudent measures to ensure the Software is securely maintained and that Customer Data is subject to security policies adequate for the proper management of health information and/or personally identifiable information. ESO will have an information security program ("Security Policies") that has been deve|oped, implemented and maintained in accordance with Industry Standards by a qualified member of its workforce. ESO shall protect City's Confidential Information in accordance with its information security program (as may be updated to remain current with Industry Standards) the current version of which is attached as Exhibit D to this Agreement. On no less than an annual bomis. ESO shall employ qusdified, industry -standard third -party auditors to perform reviews of ESO's information security program and independently assess ESO's compliance with the Security Policies. Upon receipt of written request from THE CITY OF TUKVV1LA, ESO shall provide the results of its most recent third -party security audit; such results may beinsummary form. Security and Privacy Training. ESO, at its expense, will train new and existing employees and subcontractors to comply with the data security and data privacy obligations as appropriate for its obligations to clients, including the City of Tukwila. Ongoing training is to be provided at least annually and more frequently as appropriate. 4. Security Incident / Data Breach 4.1. Security Contact. The individuals identified below shall serve as each party's designated ilEm2233027.1DOCX; 2/13175.000012/ ) moousgmEnvelope ID: mE118mo1Eoaao^ana1n Security Contact for security issues under this Agreement. CITY OPTUK%V1LA Security Contacts: Network & Security Architect: Bao Trinh Mobile: 206552-1280 Director @.CIO: Joseph Todd JosephTmddaTukvv|eVWA.cm Mobile: 206-850-9656 ESO Security Contact: Name: Patricia Perry-VNUiamm. Director of Security Compliance Address: 11500 Alterra Parkway, Suite 100 Austin, TX 78758 Phone: 866.766.9471 4.2. Requirem ents. ESO will takecommercially reasonable actions to ensure that CITY OF TUKVNLA Confidential Information under ESO's control is protected against any and all reasonably anticipated Security Incidents, induding but not limited to: (a) ESO's systems are continually monitored to detect evidence of a Security Incident (b) ESO has a Security Incidenresponse process to manage and to take corrective action for any suspected or realized Security Incident (c) IfaSecurity Incident affecting CITYOFTUKW1LA occurs, ESO, edits expense and in accordance with applicable Information Protection Lavva, will take prompt commercially reasonable action to prevent the continuation of the Security Incident. 4.3. Notification. Upon initiaawareness ofa Security Incident, ESO will notify CITY OF TUKVVLA of the incident without unreasonable delay and in no event later than five business days. 4.4. ESO will cooperate with CITY OF TUKVVILA in any investigation both parties agree is reasonably necessary toprotect the CITY C>FTUKVVLA'mrights relating tothe use, disclosure, protection and maintenance of Confidential Information. Si Confidential Information or Personal Information 5.1. Authorized Personnel. ESO will require all Authorized Personnel to meet ESO's obligations under the Agreementwith respectto Confidential Information or Personal Information. 5.2. Data and Privacy Protection Laws. ESO represents and warrants that its collection, access, use, storage, disposal, and disclosure ofPersonal Information complieswith all applicable federal, state, Iocal and foreign data and privacy protection laws, as well as all other applicable regulations and directives. ilEm2233027.1DOCX; 2/13175.000012/ ) DocuSign Envelope IIID: 61E11B861E8-31DIE8-41B21E-9549-CIF9859A53513 6. Third Party Security ESO will not outsource any work related to its products or the Services provided to CITY OF TUKWILA in countries outside the United States of America, which have not been disclosed in the Agreement or without prior written approval from CITY OF TUKWILA Legal and Information Security. If ESO desires to outsource certain work during the Term of the Agreement, ESO shall first notify CITY OF TUKWILA so that the parties can ensure adequate security protections are in place with respect to the Services provided to CITY OF TUKWILA. This Agreement constitutes acceptance by CITY OF TUKWILA of ESO's software development work in Northern Ireland, provided that no CITY OF TUKWILA Confidential Information shall be stored thereto or otherwise hosted or maintained outside of the continental United States of America. 7. Changes In the event of any change in CITY OF TUKWILA's data protection or privacy obligations due to legislative or regulatory actions, industry standards, technology advances, or contractual obligations, ESO will work in good faith with CITY OF TUKWILA to promptly amend this Exhibit accordingly. 8. Conflict in Terms. IN THE EVENT OF A CONFLICT BETWEEN THE TERMS OF THE CONTRACT FOR SERVICES, TO WHICH THIS EXHIBIT C IS ATTACHED AND THE TERMS OF ANY OTHER DOCUMENT (INCLUDING, BUT NOT LIMITED TO, THIS EXHIBIT C OR ANY OTHER EXHIBIT TO THE CONTRACT FOR SERVICES) THE TERMS OF THIS EXHIBIT C SHALL PREVAIL. llER22233027.1DOCX 2/13175.000012/'} DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 Exhibit D — ESO Information Security Policy ilERZ2233027.1DOCX; 2/13175.000012/ ) DocuSign Envelope ID: 6E11B861E8-3DIE8-41B21E-9549-CIF9859A53513 eso INFOR N SECURITY POLICY This Policy is a set of rules by which those given access to ESO systems or assets must abide. OAP • Data is central to everything ESO does for our clients. Our clients trust us to provide them with the tools and services they need to make their data useful—to them, their communities and the broader public. Most of this data is both highly sensitive and critical to our clientsservice delivery to the public. In order to be entrusted with this sensitive and critical data, we must understand that this data is both precious and vulnerable, and always act with this in mind as we help our clients. ESO expects this, our clients expect this, and the public expects this; this is the foundation for our privilege of having access to this data. This Policy serves to inform employees (and other users of our systems or assets) of their individual and organizational requirements to protect these systems and assets. In addition, ESO has processes and procedures that complement this Policy to provide additional detail. Because this Policy is essential to ESO's mission, ESO expects full, faithful, and thoughtful compliance, with it being understood that employees and other users are encouraged and expected to promptly raise questions and concerns to their managers or the Di re:,c4t,or of Secu,ritytChompliance. I ;4 le 4 oo cep ES* ,t; th thft fthk, • 14"1111" h rhte n e ,rnd;05,,& ntmr the re te* 44 ,° SCOPE: roa This Information Security Policy (this "Policy') applies to ESO Solutions, Inc. (including its subsidiaries, "ESO" or the "Company") and its employees, as well as vendors, partners and contractors providing services for ESO or to its clients, or otherwise who have access to the systems, applications, database, network, information, and resources managed or maintained by ESO ("users"). This Policy's requirements apply to (among other things): • ESO's internal applications, computer systems, networks, products, services and electronic data by ensuring adherence to all associated security standards and procedures; and • the confidentiality, integrity, and availability of Protected Health Information ("PHI") entrusted to ESO or accessible by or through ESO's products and services in compliance with the security provisions within the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), Health Information Technology for Economic and Clinical Health Act ("HITECH"), and other regulations as may be applicable or appropriate from time to time. Information Security Policy y1.0 moousgmEnvelope ID: mE11Bmo1Eoaao^ana1n eso COIVPIL NCE: Employees and other users must comply with all ESO policies, standards, and procedures, all of which are approved by ES0's Executive Management. i are hie level statements that embrace ESD^o mission, goals, objectives, and acceptable procedures. Policies state required actions and may include references to standards and procedures. Policies require compliance, and exceptions bopolicies will berare. Approved policies will be available to all pmrsonmob||gpbed bocomplying with them. Copies of policies will be maintained for six years from the date of last effectiveness, unless applicable law requires alonger retention period. TA ,oLz are mandatory actions or rules designed to support and ensure uniform application of a polions to standards, when deemed necessary, require specific approvals. �rto, nare obmp'by-etepdetails which provide direction to comply with both standards and policy. Security policies, standards, and procedures will be reviewed on an annual basis to ensure appropriate update in response to changes in the business or regulatory environment, public and customer expectations, and organizational changes that affect the security of our systems or assets. LIM Employees and other users must comply with each of the subject categories and directives outlined below. These subject categories are supplemented with separate standards and procedures, whereapplicable. Because this Policy |oessential bo ES{}^omission, ESO expects full, faithful, and thoughtfu|compliance, with it being understood that Employees and other users are encouraged and expected to promptly raise questions and concerns to their managers or the Director of Security Compliance. 1.1 Accountability. Employees and other users are responsiblefor information security, and are required to know, understand, and follow this Information Security Policy and any associated standards and procedures. 1.2 Exceptions to Standards and Procedures. Exceptions from the requirements of any approved standard or procedure will follow the directives outlined in the Risk Analysis Procedure. 1.3 Bypassing Systems Security. Employees and other users are prohibited from making attempts to compromise or bypass information systems security measures without proper authorization. Approved procedures must be followed to obtain authorization before any attempts to compromise or bypass information systems security for testing pu rposes. 1.4 Ri ht to Monitor. ESO reserves the right to monitor, inspect, or examine at any time all ESO systems and data without the consent, presence, or knowledge of the involved employees or other users. The types of information systems subject to this r|gbt of monitoring and access include, electronic messaging systems, instant messaging systems, access and resource usage reports, computer hard drives, smartphones, personal and/or shared network directories, voicemail messages, and personal storage devices and services when ES{} information is being deposited. ES{} retains Information Security Policy y1.0 2 moousgmEnvelope ID: mE118mo1Eoaao^ana1n eso the riglitto permanently remove from its systems any material it deems confidential, sensitive, proprietary, offensive, potentially illegal, inappropriate, or not consistent with the goals and objectives of ESO. 2. AMioptiitk 2.1 Employees' and other users' activities are limited to approved business purposes. 2.2 Employees and other users must protect the confidentiality, integrity, and availability of ESO systems, applications, and data entrusted to them. ESO systems, applications, and/or electronic data are not authorized for activities that are |||egp| under local, state, federal or international law. 3. 2.3 Unauthorized or U|m@p| content identified in any ESO system must be reported to appropriate ESO management or Director of Security Compliance immediately. CAVItTOIS K Logical access controls refers to the protocols used for user identification, authentication, and authorization to information systems. 3.1 All access requests must be documented and approved according to ESO standards and procedures. 3.2 All access will be approved and ganted only for authorized business purposes. 3.3 System identification (user IDs) and passwords, or other authentication methods must uniquely identify |nd|v|dua|eaccessing |nfornnat|on. 3.4 Access control procedures will follow the minimum necessary information requirements with respect to sensitive or confidential information (including PHI). 3.5 Neither employees nor other shall share their system identification and/or authentication credentials. 3.6 Employees and other users are responsible for all activities performed under their user 3.7 Employees and other users must change their passwords in compliance with access control procedures. 3.8 Passwords must meet password configuration requirements defined by the authorization and access management procedures. 3.9 User IDs should not give any indication of the administrative privilege level assigned to the account, where possible. 4. AggEmtt SAY= rily. 4.1 Employees and other users are responsible for the physical security of ESO -owned assets assigned to them. 4.2 Authentication, encryption, and other mandated security controls must be utilized on assets that contain ESO data. 4.3 See 1.3Ofor requirements |nconnection with termination of employment orservice. Information Security Policy y1.0 moousgmEnvelope ID: mE118mo1Eoaao^ana1n eso 5. 5.1 The implementation of hardware, software, and/or procedures that record and examine activity in information systems must be included in any application that processes PHI. The content and level of detail included in the activity logs must be based on an assessment of events that are most likely to be correlated with risks to the confidentiality, integrity, and availability ofthe information contained in the system. 5.2 Auditing mechanisms should record information such as the user identification associated with the event, the program or command used to initiate the event, and the time/date of the event. 5.3 Events oractions thatshould be Iogged and monitored include the following: 5.3.1 Logon attempts (includingfailed ones); 5.3.2 Changes to security settings or parameters (e.g' minimum password length); 5.3.3 Useraccounts added, changed (privileges), deactivated, and deleted; 5.3.4 Password resets; and 5.3.5 System activity reviews of applications processing electronically presented or stored PHI (ePHI). 6. 6.1 A business associate ageement is required for relationships with 'covered entities' to: 6.1.1 establish the permitted and required usesand disclosuresof PHI, 6.1.2 provide obIitions for the business associate to safeguard the information and report any uses or disclosures not provided for in the agreement, and 6.1.3 define requirements should the agreement be terminated. T. fan QQ,Btlan,Walaratitmtrit. 7.1 Changes to information resources shall be managed and executed according to a formal change control process to ensure changes are reviewed, authorized, tested, implemented, and released in a controlled manner. 7.2 A baseline configuration of all information systems must be developed, documented, and maintained. 7.3 A change request must be completed and approved prior to the commencement of any planned orscheduled maintenance. 7.4 A change request must be completed and approved prior to any changes to the 7.5 Emergency changes require the authorization and approval of Executive Management (CEO and executives that report to the CEO). 7.5.1 If services ESO provides to customers or services on which ESO depends are interrupted or non -operational, emergency changes should be handled as an Information Security Policy v1.0 4 moousgmEnvelope IID: mE11Bmo1Eoaao^ana1n eso incident as defined in the Incident Handling, Tracking, and Response procedures (see 1.16). 8. Cloud 8.1 Confidential data, including PHI, may not be uploaded to public cloud storage systems unless specifically approved by Executive Management. Public cloud storage systems include Microsoft OneDrive, Dropbox, Google Drive, iCloud, Me, or any othersimilar systems. 9. Canto C ',rations. 10. 9.1 An overall contingency plan and supporting procedures will be maintained for respondingto an emergency (e.g., system failure, fire, natural disaster, vandalism, etc.) that compromises the confidentiality, integity and/or availability of ePHI, or other business critical, confidential and/or proprietary data contained in the environment. 9.2 The documented contingency plan must include: 9.2.1 proceduresfordata backup and recovery; 9.2.2 a periodic appl ication and data analysis of the criticality ofspecific applications and data in support of the contingency plan components; 9.2.3 a disaster recovery plan (DRP); 9.2.4 an emergency mode operation plan to enable continuation of critical business processes for protection of the security of ePHI, or other mission critical, confidential, and/or proprietary data while operating i n emergency mode 9.2.5 procedures for periodic testing and revision of the overall contingency plan. 10.1 Documented procedures for creating, maintaining, and verifying retrievable exact copies of PHI and/or confidential information must be established and implemented. 10.2 Backup procedures must include a determination of the frequency, retention and the storage location of data backups based on criteria including the following: 10.2.1 Patient care impact; 10.2.2 Governmental regulations; 10.2.3 Business operations; and 10.2.4 Security best -practices. 10.3 Data backups must be performed before movement of equipment, as appropriate. 10.4 Backup media must be stored in a safe environment, preferably in a different location, and must beavailable in the event ofa system failure orother disaster. 10.5 The security of backup media must be maintained at all times during transport and storage. Information Security Policy y1.0 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso 11. Dett Chatecation. 11.1 A data classification standard will be used to classify data with respect to type and levels of sensitivity and confidentiality of the data. 11.2 Security mechanisms for storage, transmission, handling, and destruction must be implemented to have a direct correlation to the classification of the data. 12. 'ce and Mfgfil (;,on 12.1 The disposal or redeployment of electronic devices or media must not allow for the recreation or recovery of stored PHI or other sensitive, confidential, or protected data. 12.1.1 Electronic media (including storage devices, memory, or other reusable memory) will be sanitized to remove previously stored information prior to reuse or disposal. 12.1.2 The final disposition of electronic devices must be documented. 13 Erni U. 13.1 ES0's email system must be used in a professional, ethical and lawful manner. 13.2 Email containing ePHI, sensitive, or confidential information must be properly secured prior to transmission from an ESO email account. 13.3 ESO email accounts may be monitored , inspected , reproduced, and/or deleted. 13.4 ESO email accounts belong to ESO and should not be considered private. 14. Eric 14.1 All devices deployed for use on ES0's network or systems, including laptops, desktops, and personal and mobile devices configured to 'pushESO email, must be encrypted in accordance with ESO standards and procedures. No employee or other user shall disable, remove, or otherwise tamper with the encryption settings or tools on their ESO - provided devices (or attempt to do the foregoing). 15. Fa di uti letn ' trd . 15.1 A visitor log must be maintained for all non -employed staff (or individuals that would not normally require access) entering secured server areas wherein servers store ePH I or other confidential information. 15.2 All servers and network electronics must be stored in environmentally safe and secure areas. 15.3 Facility access control lists must be reviewed on a periodic basis. 15.3.1 Repairs and modifications to the physical components (i.e., hardware, walls, doors, locks) of any server closet or other area housing IT equipment must be documented and retained 15.4 ESO Management must practice appropriate security measures for terminated and transferred employees to maintain site security, data integrity and confidentiality. Information Security Policy y1.0 6 moousgmEnvelope ID: mE118mo1Eoaao^ana1n eso 16.1 Employees and other users must report suspected security incidents to Security Compliance or Executive Management immediately. 16.2 Appropriate actions to |nveetgpbe^ minimize the impact, and limit exposure of suspected incidents will be executed in accordance with ESO^m standards and proomdures. 16.3 Confirmed security incidents will be appropriately handled and tracked to ensure an effective response, timely communication and reliable evidence collection. 17.1nstant rig. 17.1 ESO instant nneosamdngeyobmnne must be used in a professional, ethical and lawful manner. 17.2 Instant messenger communications must not include PHI, confidential, or sensitive information. 17.3 Instant messages and attachments sent from or received by an ESO instant messagng system are not considered private. v 18.1 PHI must be protected from improper alteration ordestruction. 19.1n11t.mnoi,��� 19.1 All Internet activity on an ESO -provided asset must be conducted in a professional and ethical manner. 19.2 Internet activity conducted on an ESO -provided asset that would violate any local, state, or federal law is strictly prohibited. 19.3 Internet activity conducted on an ESO -provided asset is subject to inspection, disclosure, scheduled retention and disposition. 20. IF nEidious Soitourc / Anti *min. 20.1 All workstations deployed within the ESO environment must be protected from malicious software per ESOstandardsand procedures. 20.1.1 Approved security solutions installed, enabled and configured on workstations must not be modified or removed to ensure protection agp|nmt malicious software. 20.2 The intentional creation or deployment of malicious software with the ESO network is strictly prohibited. 20.3 Due to risk of viruses and malware, employees and other users must be educated to use caution when opening attachments from unknown sources, or unexpected attachments from known sources. Information Security Policy y1.0 7 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso 20.4 All devices that have the potential to infect other devices must: 20.4.1 be immediately removed or isolated from the network until they are verified as malware-free; and 20.4.2 have automatic updates, security fixes and/or patches applied. 21. Non-DWOeure C>onfilderitititly AgreeineritS. 21.1 Non -disclosure or confidentiality agreements must be completed by any vendor evaluating ESO's products, information or systems. 22. Podmeteir IDe nte etWe k Seairiti 22.1 Connections from an ESO network or device to a public network must utilize a firewall or similar perimeter defense system. 22.2 Governance of the configuration, maintenance, periodic vulnerability testing, physical security, access logs, and review of all network infrastructure equipment will be defined and documented within the standards and procedures. 22.3 Any attempt to circumvent network security or perimeter defenses is prohibited. Security testing must be pre -approved by ESO Executive Management. 22.4 Network ports and non-public wireless access points are prohibited from access without proper authorization. 23. ina and Mobile Dewir,,e 23.1 Personal or mobile devices (whether owned by the individual or provided by ESO) used to access ESO data must use a device or application password or similar security measure to lock the device or application after a specified inactivity time in the event the device is lost or stolen. 23.2 Personal and mobile devices used to access ESO data (including email) must be secured per ESO standards and procedures. 23.3 Lost or stolen personal and mobile devices containing ESO data must be reported to the Director of Security Compliance and Executive Management. 24. MEW 24.1 Documents containing PHI or other sensitive information must be removed from printers, copiers, fax machines or multi -function devices in a timely manner to avoid unauthorized viewing. 24.2 Printer memory and printer hard drives must be cleared of all ESO data prior to decommissioni ng. 25. Remote 25.1 Requests for remote access must be authorized and approved. Information Security Policy y1.0 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso 25.2 Establishing a remote connection to or th roue an ESO network from a public network requires the use of an approved secure remote access method. 25.3 Attempts to bypass security measures and/or activities involving the compromise of security measures is prohibited unless authorized by ESO Executive Management. 25.4 Only the applications, systems, and/or electronic data authorized by an approved remote access request may be accessed. 25.4.1 Any unauthorized attempt to access applications, systems and/or electronic data is prohibited. 25.5 All remote access connections must connect through a perimeter security device. 25.6 All network traffic is subject to inspection, disclosure, scheduled retention and d isposition. 26. Risk is and Risk Mama ent. 26.1 A periodic risk analysis must be completed that identifies all known risks associated with systems containing PHI and other confidential information. 26.2 A risk management plan must be completed to address all risks identified in the periodic risk analysis. 27. Sanction. 27.1 Employees and other users will be subject to disciplinary action up to and including termination if this policy and/or any associated standards and procedures are not adhered to. 28 iiiiiarerieas arid Trainitig, 28.1 A security awareness and training program must be implemented for all employees. 28.1.1 Verification of employee training must be maintained. 28.2 Security updates must be provided to employees periodically and as circumstances warrant. 29. "ibilmomm n katiOn5. 29.1 Only authorized telecommunication platforms are to be used for conducting ESO business. 30. 1rntior and it'll [Rear. 30.1 Managers of terminated or transferred employees or other users must initiate the termination or transfer request upon notification of the termination or transfer before / on the effective date of the termination or transfer. 30.2 Managers must ensure that appropriate access levels are given to or removed from employees and other users they supervise based on least privileges and minimum necessary information requirements. Information Security Policy y1.0 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso 30.3 Managers of terminated employees and other users are responsible for recovering ID badges and other ESO property (e.g., laptop PCs, tablets, proximity cards, keys, and other ESO -assigned assets) from terminated employees and other users. 30.4 All termination requests are to be considered confidential. 31. Iblid,...NLV 31.1 Third parties provided access to ESO's network must comply with ESO's security policies, standards, and procedures. 32. Transadesion S4curhy. 32.1 Precautions must be taken to protect sensitive data, including PHI, from unauthorized access, and intentional or unintentional loss or modification while in transit over an open network. 33. ;le 34 rtthH 111 *Ina men 33.1 Periodic vulnerability assessment scans will be conducted to identify security vulnerabilities within ESO's network. 33.1.1 Identified vulnerabilities will be managed, mitigpted, and remediated in a timely manner. 34.1 All wireless access points on the ESO network must be approved and will be centrally managed by ESO. 34.2 Unauthorized access points are prohibited. 34.2.1 If an unauthorized access point is identified, it will be removed immediately. 34.3 Any individual using a personal wireless device is prohibited from attaching the device to any ESO non-public wireless network without proper authorization. 34.4 Except for authorized security testing as defined by ESO procedures, any attempt to circumvent the ESO wireless security controls for wireless access to or though the ESO network is prohibited. 35. 35.1 Employees and other users must comply with standards regarding the proper use and security of workstations, including the following provisions: 35.1.1 Physical safeguards must be implemented to allow access only by authorized users. 35.1.2 Any stationary computer screens that display ePHI within clear view of unauthorized individuals must be repositioned or equipped with privacy screens. Information Security Policy v1.0 10 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso 35.1.3 Workstations in areas that are vulnerable to theft must be protected using appropriate protection procedures and/or antitheft technologies. 35.1.4 No unlicensed software may be installed on any ESO system or device. Information Security Policy y1.0 11 DocuSign Envelope ID: 6E118861E8-3DIE8-41821E-9549-CIF9859A53513 eso ?AL Approval Date: November 9, 2018 P LI Y RE ISDN HI (TORY Version Date Remarks 1.0 November 1, 2018 Original Issue Information Security Policy y1.0 12 Certificate Of Completion Envelope Id: 61E1B861E831DE84B21E9549C1F9859A53513 Subjlect: IPlease DocuSign: US - ESO - Tukwila IFD - ESO Contract for Services with lExhibits -1Final.pdf Source Envelope: Document Pages: 34 Signatures: 2 Certificate Pages: 5 Initials: 0 AutoNav: Enabled lEnvelopeld Stamping: Enabled Time Zone: (UTC -08:00) Pacific Time (US & Canada) Record Tracking Status: Original 9/23/2020 11:34:05 AM Signer Events Matt Walker mattwalker@eso.com COO Security Level:lEmail, Account Authentication (None) Electronic Record and Signature Disclosure: Accepted: 9/24/2020 8:48:03 AM ID: 631 el 0b4-2234-48c8-8462-263cb234ed44 In Person Signer Events Editor Delivery Events Agent Delivery Events Intermediary Delivery Events Certified Delivery Events Carbon Copy Events Robert Munden robertmunden@eso.com General Counsel & Secretary ESO SOIUTIONS, INC. Security Level:lEmail, Account Authentication (None) Electronic Record and Signature Disclosure: Not Offered via DocuSign Witness Events Notary Events Envelope Summary Events Envelope Sent Certified Delivered Signing Complete Completed Holder: Eddie Cruz Eddie.Cruz@esosolutions.com Signature [DocuSig ned by: Ault 04111,r ,,41193.1(19B.11 4,0 Signature Adoption: Pre -selected Style Using IP Address: 12.132.220.135 Sig nature Status Status Status Status Status COPIED Signature Signature Status Hashed/Encrypted Security Checked Security Checked Security Checked Status: Completed Envelope Originator: Eddie Cruz Eddie.Cruz@esosolutions.com IP Address: 70.112.204.17 Location :IDocuSign Timestamp Sent: 9/23/2020 11:49:19 AM Resent 9/24/2020 7:31:03 AM Resent 9/24/20207:34:21 AM Viewed: 9/24/2020 8:48:03 AM Signed: 9/24/2020 8:48:20 AM Timestamp Timestamp Timestamp Timestamp Timestamp Timestamp Sent: 9/23/2020 11:49:20 AM Timestamp Timestamp Ti mestam ps 9/24/2020 7:34:21 AM 9/24/2020 8:48:03 AM 9/24/2020 8:48:20 AM 9/24/2020 8:48:20 AM Payment Events Status Timestamps Electronic Record and Sicnatur Disclosure Electronic Record and Signature Disclosure created on: 5/16/2017 9:37:10 AM Paries agreed to: Matt Walker CONSUMER DISCLOSURE From time to time, ESO Solutions (we, us or Company) may be required by law to provide to you certain written n.oti.ces or disclosures. Described below are the terms and conditions for providing to you such notices and disclosures electronically through the DocuSign, Inc. (DocuSi.gn) electron.i.c signing system. Please read the information below carefully and thoroughly, and if you can access this information electronically to your satisfaction and agree to these terms and conditions, please confirm. your agreement by clicking the 'I agree' button at the bottom of this document. Getting paper copies At any ti.m.e, you may request from us a paper copy of any record provided or made available electronically to you by us. You will have the ability to download and print documents we send to you through the DocuSign system during and immediately after signing session and, if you elect to create a DocuSign signer account, you may access them for a 1.im.ited period of ti.m.e (usually 30 days) after such documents are first sent to you. After such time, if you wish for us to send you paper copies of any such documents from. our office to you, you will be charged a, $0.00 per -page fee. You may request delivery of such paper copies from us by following the procedure described below. Withdrawing your consent If you decide to receive notices and disclosures from us electronically, you may at any time change your mind and tell us that thereafter you want to receive required notices and disclosures only in paper format. How you must inform us of your decision to receive future notices and disclosure in paper lbrinat and withdraw your consent to receive notices and disclosures electronically is described below. Consequences of changing your mind. H you elect to receive required notices and disclosures only in paper format, il will slow the speed at which we can complete certain steps in transactions with you and delivering services to you because we will need first to send the required notices or disclosures to you in paper lbrmat, and then wait until we receive back Froin you your acknowledgment of your receipt of such. paper notices or disclosures. To indicate to us that you are changing your mind, you must withdraw your consent using the DocuSign 'Withdraw Consent' form on the signing page of a, DocuSign envelope instead of signing it. This will indicate to us that you have withdrawn your consent to receive required notices and disclosures electronically from us and you will no longer be able to use the DocuSign system to receive required notices and consents electronically from. us or to sign electronically documents from us. All notices and disclosure's will be sent to you electronically Unless you tell us otherwise in accordance with the procedures described herein, we will provide electronically to you through the DocuSign system all required n.oti.ces, disclosures, authorizations, a.cknowledgements, and other documents that are required to be provided or made available to you during the course of our relationship with you. To reduce the chance of you inadvertently not receiving any notice or disclosure, we prefer to provide all of the required notices and disclosures to you by the same method and to the same address that you have given. us. Thus, you can receive all the disclosures and notices electronically or in paper format through. the paper mail delivery system. If you do not agree with this process, please let us know as described below. Pease also see the paragraph imm.ediately above that describes the consequences of your electing not to receive delivery of the notices and disclosures electronically from us.. How to contact ESO Solutions: You may contact us to let us know of your changes as to how we may contact you electronically, to request paper copies of certain information from us, and to withdraw your prior consent to receive notices and disclosures electronically as follows: To contact us by email send messages to: peter.quadrino@esosolutions.com To advise ESO Solutions of your new e-mail address To let us know of a, change in your e-mail address where we should send n.oti.ces and disclosures electronically to you, you must send an email message to us al. peter.quadrino@esosolutions.coni. and in the body of such request you must state: your previous e-mail address, your new e-mail address. We do not require any other information from. you to change your email address.. In addition, you must notify DocuSign. Inc. to arrange for your new email address to be reflected in your DocuSign account by 1bl:towing the process for changing e-mail in the DocuSi.gn system. To request paper copies from ESO Solutions To request delivery from us of paper copies of the notices and disclosures previously provided by us to you electronically, you must send us an e-mail to peter.quadrin.o@esosolutions,comand in the body of such request you must state your e-mail address, full name, US Postal address, and. tel.eph.one number. We will bill you for any fees at that time, if any. To withdraw your consent with ESO Solutions To inform us that you no longer want to receive future notices and discosures in electronic format you may: 1. decline to sign a document from within your DocuSign session, and on the subsequent page, select the check -box indicating you wish to withdraw your consent, or you may; H. send us an e-mai.l. peter.quadrino@esosolutions.comand in the body of such request you must state your ,full. name, US Postal Address, and telephone number. We do not need any other information from you to withdraw consent.. The consequences of your withdrawing consent for online documents will be that transactions may take a, longer time to process.. Required hardware and software Operating Windows® 2000, Windows® XP, Windows Vista®; Mac OS® X Systems: Browsers: PDF Reader: Acrobat® or similar software may be required 10 view and print PDF files Fina release versions of Internet ,Explorer® 6.0 or above (Windows only); Mozilla Firefox 2.0 or above (Windows and Mac); SafaIiTM 3.0 or above (Mac only) Screen 800 x 600 minimum Resolution: Enabled Security Settings: " These minimum. requirements are subject to change. If these requirements change, you will be asked to re -accept the disclosure. Pre-release (e.g. beta) versions of operating systems and browsers are n.ot supported. Acknowledging your access and consent to receive materials electronically. To confirmto us that you can access this information electronically, which will be similar to other electronic notices and disclosures that we will provide to you, please verify that you were able to read this electronic disclosure and that you also were able to print on paper or electronically save this page for your f.uture reference and access or that you were able to e-mail this disclosure and consent to an address where you will be able to print on paper or save it for your future reference and access. Further, if you consent to receiving notices and disclosures exclusively in electronic format on the terms and conditions described above, pease let us know by clicking the 'I agree' button below. By checking the 'I agree' box, I confirm that: Allow per session cookies I can access and read this Electronic CONSENT TO ELECTRONIC RECEIPT OF ELECTRONIC CONSUMER DISCLOSURES document; and I can print on paper the disclosure or save or send the disclosure to a place where I can print it, for future reference and access; and Until or unless I notify ESO Solutions as described above, I consent to receive from exclusively through electronic means all notices, disclosures, authorizations, a.cknowledgements, and other documents that are required to be provided or made available to me by ESO Solutions during the course of my relationship with you.