This Data Security Guidelines (鈥淒SG鈥 or 鈥淪ecurity Guidelines鈥) document sets forth the duties and obligations of 爆走黑料 (defined below) with respect to the security of Personal Information (defined below).聽 In the event of any inconsistencies between the DSG and the Agreement (defined below), the parties agree that the DSG will supersede and prevail.聽 Capitalized terms not defined herein shall have the meaning ascribed to them in the Agreement.
- Definitions.
- "Agreement" means the Agreement for the Services between the 爆走黑料 LLC entity (鈥爆走黑料鈥) and Subscriber incorporating the Privacy Notice to which these Security Guidelines are referenced and made a part thereof.
- "Applicable Laws" means federal, state and international privacy, data protection and information security-related laws, rules and regulations applicable to the Services and to Personal Information.
- "End User Data" means the data provided to or collected by 爆走黑料 in connection with 爆走黑料鈥檚 obligations to provide the Services under the Agreement.
- "Personal Information" means information provided to 爆走黑料 in connection with 爆走黑料鈥檚 obligations to provide the Services under the Agreement that (i) could reasonably identify the individual to whom such information pertains, such as name, address and/or telephone number or (ii) can be used to authenticate that individual, such as passwords, unique identification numbers or answers to security questions or (iii) is protected under Applicable Laws. For the avoidance of doubt, Personal Information does not include aggregate, anonymized data derived from an identified or identifiable individual.
- "Processing of Personal Information" means any operation or set of operations which is performed upon Personal Information, such as collection, recording, organization, storage, use, retrieval, transmission, erasure or destruction.
- "Third Party" means any entity (including, without limitation, any affiliate, subsidiary and parent of 爆走黑料) that is acting on behalf of, and is authorized by, 爆走黑料 to receive and use Personal Information in connection with 爆走黑料鈥檚 obligations to provide the Services.
- "Security Incident" means a confirmed, unsecured, unlawful access to, acquisition of, disclosure of, loss, or use of Personal Information which poses a significant risk of financial, reputational or other harm to the affected End User or Subscriber.
- "Services" means any services and/or products provided by 爆走黑料 in accordance with the Agreement.
- Confidentiality and Non-Use; Consents.
- 爆走黑料 agrees that the Personal Information is the Confidential Information of Subscriber and, unless authorized in writing by Subscriber or as otherwise specified in the Agreement or this DPSG, 爆走黑料 shall not Process Personal Information for any purpose other than as reasonably necessary to provide the Services, to exercise any rights granted to it under the Agreement, or as required by Applicable Laws.
- 爆走黑料 shall maintain Personal Information confidential, in accordance with the terms set forth in this Security Guidelines and Applicable Laws.聽 爆走黑料 shall require all of its employees authorized by 爆走黑料 to access Personal Information and all Third Parties to comply with (i) limitations consistent with the foregoing, and (ii) all Applicable Laws.
- Subscriber represents and warrants that in connection with any Personal Information provided directly by Subscriber to 爆走黑料, Subscriber shall be solely responsible for (i) notifying End Users that 爆走黑料 will Process their Personal Information in order to provide the Services and (ii) obtaining all consents and/or approvals required by Applicable Laws.聽聽
- Data Security: 爆走黑料 shall use commercially reasonable administrative, technical and physical safeguards designed to protect the security, integrity, and confidentiality of Personal Information.聽 爆走黑料's security measures include the following:聽
- Access to Personal Information is restricted solely to 爆走黑料鈥檚 staff who need such access to carry out the responsibilities of 爆走黑料 under the Agreement.
- Access to computer applications and Personal Information are managed through appropriate user ID/password procedures.
- Access to Personal Information is restricted solely to Subscriber personnel based on the user role they are assigned in the system (provided, however, that it is the Subscriber鈥檚 responsibility to ensure that user roles match the level of access allowed for personnel and that their personnel comply with Applicable Law in connection with use of such Personal Information).
- Data is encrypted in transmission (including via web interface) and at rest at no less than 256-bit level encryption.
- 爆走黑料 or a 爆走黑料 authorized party performs a security scan of the application, computer systems and network housing Personal Information using a commercially available security scanning system on a periodic basis.
- Security Incident.
- In the event of a Security Incident, 爆走黑料 shall (i) investigate the Security Incident, identify the impact of the Security Incident and take commercially reasonable actions to mitigate the effects of any such Security Incident, (ii) timely provide any notifications to Subscriber or individuals affected by the Security Incident that 爆走黑料 is required by law, subject to applicable confidentiality obligations and to the extent allowed and/or required by and not prohibited by Applicable Laws or law enforcement.
- Except to the extent prohibited by Applicable Laws or law enforcement, 爆走黑料 shall, upon Subscriber鈥檚 written request and to the extent available, provide Subscriber with a description of the Security Incident and the type of data that was the subject of the Security Incident.
- 爆走黑料鈥檚 obligation to report or respond to a Security Incident is not and will not be construed as an acknowledgement by 爆走黑料 of any fault or liability with respect to the Security Incident.
- Security Questionnaire.
- Upon written request by Subscriber, which request shall be no more frequently than once per twelve (12) month period, 爆走黑料 shall respond to security questionnaires provided by Subscriber, with regard to 爆走黑料's information security program applicable to the Services, provided that such information is available in the ordinary course of business for 爆走黑料 and it is not subject to any restrictions pursuant to 爆走黑料鈥檚 privacy or data protection or information security-related policies or standards.聽 Disclosure of any such information shall not compromise 爆走黑料鈥檚 confidentiality obligations and/or legal obligations or privileges. Additionally, in no event shall 爆走黑料 be required to make any disclosures prohibited by Applicable Laws. All the information provided to Subscriber under this section shall be Confidential Information of 爆走黑料 and shall be treated as such by the Subscriber.聽
- Security Audit.
- Upon written request by Subscriber, which request shall be no more frequently than once per twelve (12) month period, 爆走黑料's data security measures may be reviewed by Subscriber through an informal audit of policies and procedures or through an independent auditor鈥檚 inspection of security methods used within 爆走黑料's infrastructure, storage, and other physical security, any such audit to be at Subscriber鈥檚 sole expense and subject to a mutually agreeable confidentiality agreement and at mutually agreeable timing, or, alternatively, 爆走黑料 may provide Subscriber with a copy of any third party audit that 爆走黑料 may have commissioned.聽聽
- Records Retention and Disposal.
- Subscriber may access, correct, and delete any Personal Information in 爆走黑料鈥檚 possession by submitting 爆走黑料鈥檚 Personal Information Request Form: .
- 爆走黑料 will use commercially reasonable efforts to retain End User Data in accordance with 爆走黑料鈥檚 End User Data retention policies.聽聽
updated 1/30/26