(xx) Sanctions. Neither the Company nor any of its subsidiaries, directors, officers, or employees, nor, to the knowledge of the Company, any agent, affiliate or other person acting on behalf of the Company or any of its subsidiaries is currently the subject or the target of any U.S. sanctions administered or enforced by the Office of Foreign Assets Control of the U.S. Department of the Treasury or the U.S. Department of State, the United Nations Security Council, the European Union, His Majesty’s Treasury of the United Kingdom, or other relevant sanctions authority (collectively, “Sanctions”); nor is the Company or any of its subsidiaries located, organized or resident in a country or territory that is the subject or the target of Sanctions, including, without limitation, Crimea, Cuba, Iran, North Korea, Syria and the so called Donetsk People’s Republic and the so called Luhansk People’s Republic located in Ukraine (each, a “Sanctioned Country”); and the Company will not, directly or indirectly, use the proceeds of this offering, or lend, contribute or otherwise make available such proceeds to any subsidiary, or any joint venture partner or other person or entity, for the purpose of unlawfully funding or financing the activities of or business with any person, or in any country or territory, that, at the time of such funding or financing, is the subject or the target of Sanctions or in any other manner that will result in a violation by any person (including any person participating in the transaction whether as underwriter, advisor, investor or otherwise) of applicable Sanctions. For the past five years, the Company and each of its subsidiaries have not engaged in and are not now engaged in any unlawful dealings or transactions with any person that at the time of the dealing or transaction is or was the subject or the target of Sanctions or with any Sanctioned Country.
(yy) Cybersecurity. The Company and its subsidiaries’ information technology assets and equipment, computers, systems, networks, hardware, software, websites, applications, and databases (collectively, “IT Systems”) are adequate for, and operate and perform in all material respects as required in connection with the operation of the business of the Company and its subsidiaries as currently conducted, and to the Company’s knowledge, are free and clear of all material bugs, errors, defects, Trojan horses, time bombs, malware and other corruptants. The Company and its subsidiaries have implemented and maintain commercially reasonable physical, technical and administrative controls, policies, procedures, and safeguards to maintain and protect their material confidential information and the integrity, continuous operation, redundancy and security of all IT Systems and data, including “Personal Data,” used in connection with their businesses. “Personal Data” means (i) a natural person’s name, street address, telephone number, e-mail address, photograph, social security number or tax identification number, driver’s license number, passport number, credit card number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; and (iii) any other piece of information that allows the identification of such natural person as defined or described in applicable Privacy Laws (as defined below). There have been no breaches, violations, outages or unauthorized uses of or accesses to same, except for those that have been remedied without material cost or liability, nor are there any incidents under internal review or investigations relating to the same. The Company and its subsidiaries are presently in material compliance with all applicable Privacy Laws, internal policies and contractual obligations relating to the privacy and security of IT Systems and Personal Data and to the protection of such IT Systems and Personal Data from unauthorized use, access, misappropriation or modification. Neither the Company nor its subsidiaries (i) conduct any operations in the European Union or the European Economic Area or maintain any “personal data”, as defined by the European Union General Data Protection Regulation (EU 2016/679) within either the European Union or the European Economic Area or (ii) is a covered entity, business associate, or otherwise receives any protected health information as such terms are defined under HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act.
(zz) Compliance with Data Privacy Laws. The Company and its subsidiaries are in material compliance with all applicable data privacy and security laws and regulations (collectively, the “Privacy Laws”). The Company and its subsidiaries have complied and are presently in compliance in all material respects with their respective policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling and processing of Personal Data (the “Policies”). The Company and its subsidiaries have at all times made all disclosures to users or customers required by Privacy Laws, and none of such disclosures made or contained in any Policy have, to the knowledge of the Company, been inaccurate or in violation of any Privacy Laws in any material respect. The Company further certifies that neither it nor any subsidiary: (i) has received any written notice of any actual or
15