(o) The Company is, and in the past at all times has made itself, in compliance with each Applicable Privacy and Data Security Requirement. At all times since inception, the Company has maintained a policy or policies that govern its collection, use, storage, retention, disclosure, and disposal of Personal Information (each, a “Privacy Policy”), provided notice of its Privacy Policy on all of its websites and mobile applications in a manner compliant with all Applicable Privacy and Data Security Requirements, and given all notices and obtained all consents, rights and permissions required by its Privacy Policy and all Applicable Privacy and Data Security Requirements, including as required to permit the transfer of Personal Data in connection with the transactions contemplated by this Agreement, and such transfer will not violate in any material respect any Privacy Policy or Applicable Privacy and Data Security Requirements. The Company’s Privacy Policies fully and accurately disclose how the Company Processes Personal Information. Complete and correct copies of all Privacy Policies have been made available to Parent.
(p) The Company has implemented, maintains and complies with a privacy compliance program that is comprised of appropriate internal processes, policies and controls designed to comply with each Applicable Privacy and Data Security Requirement, including processes for providing notice and obtaining and maintaining records of verifiable parental consent regarding the processing of Personal Information about children under the age of 13. The Company complies with all requirements of each self-certification program the Company has subjected itself to, including all certifications, seals and safe-harbor programs relating to the Processing of Personal Information.
(q) All Software, systems, servers, computers, hardware, firmware, middleware, networks, data communications lines, routers, hubs, switches and other information technology equipment used in the operation of the Company’s business (collectively, the “Company Systems”) are adequate for, and operate and perform in all material respects in accordance with their documentation and functional specifications and otherwise as required in connection with, the operation of such businesses. The Company Systems directly controlled and managed by the Company have not materially malfunctioned or failed within the past four years. The Company has implemented commercially reasonable backup, security and disaster recovery technology consistent with industry standard practices, and, to the Company’s Knowledge no Person has gained unauthorized access to any Company Systems. The Company Systems do not have any material security vulnerabilities.
(r) At all times during the last five years, the Company has implemented and maintained an information security program which implements and monitors administrative, organizational, and technical measures to protect against anticipated or actual threats to the security, confidentiality, availability and integrity of Company Systems, including all Personal Information and all other confidential or proprietary information processed by or on behalf of the Company (collectively, “Protected Information”). The Company’s information security program is reasonably consistent with (i) reasonable practices in the industry in which the Company operates, and (ii) the Company’s Applicable Privacy and Data Security Requirements.
(s) There has been no incidents of, or third-party claims alleging unauthorized access, unauthorized acquisition, unauthorized destruction, unauthorized use, unauthorized disclosure, loss, damage, corruption, alteration, or other misuse of any Company Systems or Protected Information (each, a “Security Breach”). The Company has not been notified in writing, or been required by any Applicable Privacy and Data Security Requirements or Governmental Body to notify in writing, any Person of any Security Breach. No claims, allegations, investigations, inquiries, enforcements, complaints, or Legal Proceedings are pending or, to the
38