Skip to Main Content

Information Security Terms

These Information Security Terms (“Security Terms”) shall apply to Appriss Retail’s provision of one or more Products and/or Services to You pursuant to a validly executed Order Form.  These Security Terms are incorporated into the Appriss’ Master License and Services Agreement, available here: https://apprissretail.com/mlsa/ (“MLSA”).  All capitalized terms that are not expressly defined in these Terms will have the meanings given to them in the MLSA, the DPA (available here: https://apprissretail.com/dpa/, or the applicable Order Form. In the event of a conflict between these Security Terms and the MLSA or DPA, the MLSA or DPA shall control, except where these Terms impose a more stringent security obligation, in which case this Security Terms shall control with respect to that specific requirement.  

1. Scope.

These Terms applies to Appriss Retail’s collection, storage, transmission, use, and disposal of Your Data in connection with the Appriss Retail Platform, Modules, and Services, and to the systems and personnel through which Appriss Retail processes Your Data. For the avoidance of doubt, general obligations regarding confidentiality, subprocessor management, data subject rights, prohibited uses of Your Data, data deletion, and general compliance with applicable law are governed by the MLSA and DPA; these Terms addresses specific technical and operational security controls not otherwise detailed therein. 

2. Cardholder Data Exclusion.

The Appriss Retail Platform and Modules are not designed or intended for the submission, storage, or transmission of payment card data or cardholder data. Appriss Retail does not collect or process primary account numbers, payment card numbers, Consumer PINs, bank account numbers, or social security or national identification numbers through the Appriss Retail Platform or Modules and does not require such information to provide the Services. You shall not use the Appriss Retail Platform or Modules to submit, store, or transmit payment card data or cardholder data, as those terms are defined under PCI-DSS. Your transmission of any such information to Appriss Retail in violation of this restriction shall be at Your sole risk and liability, and Appriss Retail shall have no obligation to secure, protect, or return any such data. 

3. Information Security Program. 

  1. Appriss Retail shall maintain a written information security program (“ISP”) managed by Appriss’ Director of Information Security, or an employee in an equivalent role, that includes physical, administrative, and technical controls for the security, confidentiality, and integrity of Your Data.  
  2. The ISP shall address the collection, storage, access, transmission, and disposal of Your Data and shall include: (a) a written plan to assess and manage system failures; (b) regular assessment of data security risks and revision of the program to address identified risks; and (c) notice and incident response procedures consistent with these Terms. 
  3. The ISP shall be reviewed and updated no less than annually. 
  4. Appriss Retail’s ISP shall be maintained consistent with the ISO 27001 framework, as applicable to Appriss Retail’s operations and services. 

4. Access Controls.

Appriss Retail shall implement and maintain access controls limiting access to Your Data to personnel who require such access to perform the Services. Such controls shall include, at minimum:

  1. Role-based access controls applying least-privilege principles; 
  2. multi-factor authentication for remote access and for access to systems that store or process Your Data; 
  3. unique user credentials; shared or generic accounts with access to Your Data are prohibited; 
  4. periodic recertification of user access rights, no less than annually;  
  5. prompt deprovisioning of access upon termination or role change; and 
  6. event logging sufficient to record access to and activity within systems that store or process Your Data, including authentication events, privileged access, and administrative actions; such logs shall be retained for no less than twelve (12) months and protected against unauthorized modification or deletion.  

5. Encryption. 

Appriss shall encrypt Your Data: (a) in transit, using industry-standard protocols (TLS 1.2 or higher, or equivalent); and (b) at rest, using industry-standard encryption (AES-256 or equivalent). Upon written request, Appriss Retail shall encrypt any Data stored on its information systems or transmitted to You, to the extent not already done as a standard practice. Appriss Retail shall maintain key management procedures consistent with industry best practices. 

6. Vulnerability Management and Penetration Testing. 

  1. Vulnerability Management. Appriss Retail shall maintain a vulnerability management program that includes vulnerability scanning of in-scope systems at regular intervals consistent with industry best practices, with remediation prioritized based on risk severity. The program shall address, at a minimum: 
    1. vulnerabilities identified in the OWASP Top Ten Project (available at http://www.owasp.org) and comparable recognized industry threat intelligence sources; 
    2. host and network-based vulnerability surveillance; and 
    3. network and application security controls including, where applicable, protections against common application-layer threats. 
  2. Penetration Testing. No less than once per year during the Term, Appriss Retail shall engage a reputable, qualified third-party assessor certified by recognized industry standards to conduct a penetration test of Appriss Retail’s select application and infrastructure used to deliver the Services. Appriss Retail will discuss the general results of such testing with You upon request in a manner that does not expose specific vulnerabilities to broader disclosure. To the extent a material security weakness is identified, Appriss Retail will take appropriate remediation action. You are prohibited from independently conducting penetration testing on Appriss Retail’s applications or infrastructure. 

7. Incident Notification. 

The DPA governs Appriss Retail’s notification obligations regarding Security Incidents affecting Personal Data. 

8. Certification; Third-Party Hosting. 

  1. Certification Report. Upon Your written request (no more than once annually, or in connection with a confirmed Security Incident), Appriss Retail shall provide You with proof of its most recent ISO 27001 certification, SOC 2 report, or equivalent recognized industry certification or assessment covering the relevant infrastructure used to host the Modules and store Your Data (“Certification Report”). A current, valid Certification Report provided under this Section shall constitute sufficient evidence of compliance with Appriss Retail’s security program obligations under this ISA for the period covered by the report. 
  2. Third-Party Hosting. Appriss Retail shall not engage a third party to host Your Data without requiring that third party to maintain an annual information security certification comparable to the Certification Report described in Section 8(a), or to otherwise demonstrate compliance with security standards consistent with Section 3(c) of this ISA. For the avoidance of doubt, co-location facilities where Appriss Retail maintains control over servers and computers but leases space, equipment, or power supply do not constitute third-party hosted servers for purposes of this Section. 

9. Workforce Security. 

Appriss Retail shall: (a) advise all employees, agents, and third-party contractors who have access to Your Data of the confidential and sensitive nature of such information prior to granting access, through training or equivalent processes; (b) limit access to Your Data to those with a demonstrated need for such access in order to perform Appriss Retail’s obligations under the MLSA; and (c) remain responsible for compliance by its employees, agents, and third parties with the obligations under these Terms and the MLSA. 

10. Business Continuity and Disaster Recovery Plans.

  1. Appriss Retail shall maintain written business continuity and disaster recovery plans (“BC/DR Plans”) applicable to the systems, infrastructure, and operations used to deliver the Services. The BC/DR Plans shall address, at minimum:
    1. identification of critical systems and data required to restore the Services following a disruption;
    2. defined recovery time objectives (“RTO”) and recovery point objectives (“RPO”) for systems that store or process Your Data;
    3. procedures for restoring system availability and data integrity following a failure, disaster, or other disruption event; and
    4. roles and responsibilities of personnel involved in executing recovery procedures.
  2. Appriss Retail shall test its BC/DR Plans no less than once per year, document the results of such testing, and remediate material deficiencies identified through testing within a reasonable timeframe.
  3. In the event of a system failure, disaster, or other disruption that materially impacts the availability of the Services or the integrity of Your Data, Appriss Retail shall notify You as promptly as practicable under the circumstances and shall keep You reasonably informed of recovery status and estimated restoration timelines.
  4. Upon reasonable written request (no more than once per twelve (12) month period, except in connection with a confirmed disruption event), Appriss Retail shall provide You with a written summary of its BC/DR posture, including current RTO and RPO targets, at a level of detail that does not require disclosure of sensitive security information.

11. Audit Rights. 

The DPA governs your audit rights regarding Appriss Retail’s access to and use of Personal Data. 

12. General Provisions. 

  1. Survival. These Terms shall survive termination of the MLSA for so long as Appriss Retail retains any of Your Data. 
  2. Order of Precedence. These Terms are subject to the Order of Precedence provision of the MLSA. Where these Terms imposes a more specific security obligation than the MLSA body, these Terms controls that specific obligation. These Terms do not supersede or limit the DPA; both apply concurrently and shall be read harmoniously where possible. 
  3. Severability.  If any provision of these Terms is unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remainder of these Terms shall remain in full force and effect.