available such proceeds to any subsidiary, or any joint venture partner or other person or entity, for the purpose of financing the activities of or business with any person, or in any country or territory, that at the time of such financing, is the subject or the target of Sanctions or in any other manner that will result in a violation by any person (including any person participating in the transaction whether as underwriter, advisor, investor or otherwise) of applicable Sanctions. For the past five years, the Company and its subsidiaries have not knowingly engaged in and are not now knowingly engaged in any dealings or transactions with any person that at the time of the dealing or transaction is or was the subject or the target of Sanctions or with any Sanctioned Country.
(ss)Sarbanes-Oxley. There is, and has been, no failure on the part of the Company or any of the Company’s directors or officers, in their capacities as such, to comply with any applicable provision of the Sarbanes-Oxley Act of 2002, as amended, and the rules and regulations promulgated in connection therewith, including Section 402 related to loans and Sections 302 and 906 related to certifications.
(tt)Cybersecurity. The Company’s and its subsidiaries’ information technology assets and equipment, computers, systems, networks, hardware, software, websites, applications, and databases (collectively, “IT Systems”) are adequate for, and operate and perform in all material respects as required in connection with the operation of the business of the Company and its subsidiaries as currently conducted, free and clear of all material bugs, errors, defects, Trojan horses, time bombs, malware and other corruptants. The Company and its subsidiaries have implemented and maintained commercially reasonable physical, technical and administrative controls, policies, procedures, and safeguards to maintain and protect their material confidential information and the integrity, continuous operation, redundancy and security of all IT Systems and data, including “Personal Data,” used in connection with their businesses. “Personal Data” means (i) a natural person’s name, street address, telephone number, e-mail address, photograph, social security number or tax identification number, driver’s license number, passport number, credit card number, bank information, or customer or account number; (ii) any information which would qualify as “personally identifying information” under the Federal Trade Commission Act, as amended; (iii) “personal data” as defined by GDPR; (iv) any information which would qualify as “protected health information” under the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act (collectively, “HIPAA”); and (v) any other piece of information that allows the identification of such natural person, or his or her family, or permits the collection or analysis of any data related to an identified person’s health or sexual orientation. Except as would not, individually or in the aggregate, reasonably be expected to result in a Material Adverse Change, there have been no breaches, violations, outages or unauthorized uses of or accesses to same, except for those that have been remedied without material cost or liability or the duty to notify any other person, nor any material data incidents under internal review or investigations relating to the same. The Company and its subsidiaries are presently in material compliance with all applicable laws or statutes and all judgments, orders, rules and regulations of any court or arbitrator or governmental or regulatory authority, internal policies and contractual obligations relating to the privacy and security of IT Systems and Personal Data and to the protection of such IT Systems and Personal Data from unauthorized use, access, misappropriation or modification.
(uu)Compliance with Data Privacy Laws. The Company and its subsidiaries are, and at all prior times since January 1, 2018 were, in material compliance with all applicable state and federal data privacy and security laws and regulations, including without limitation HIPAA, and the Company and its subsidiaries have taken commercially reasonable actions to prepare to comply with, and since May 25, 2018, have been and currently are in compliance with, the European Union General Data Protection Regulation (“GDPR”) (EU 2016/679) (collectively, the “Privacy Laws”). To ensure compliance with the Privacy Laws, the Company and its subsidiaries have in place, comply with, and take appropriate steps reasonably designed to ensure compliance in all material respects with their policies and procedures relating to data privacy and security and the collection, storage, use, disclosure, handling, and analysis of Personal Data (the “Policies”). The Company and its subsidiaries have at all times since January 1, 2018 made all disclosures to users or customers required by applicable laws and regulatory rules or requirements, and none of such disclosures made or contained in any Policy have, to the knowledge of the Company, been inaccurate or in violation of any applicable laws and regulatory rules or requirements in any material respect. The Company further certifies that neither it nor any subsidiary: (i) has received notice of any actual or potential liability under or relating to, or actual or potential violation of, any of the Privacy Laws, and has no knowledge of any event or condition that would reasonably be expected to result in any such notice; (ii) is currently conducting or paying for, in whole or in part, any investigation, remediation, or other corrective action pursuant to any Privacy Law; or (iii) is a party to any order, decree, or agreement that imposes any material obligation or liability under any Privacy Law.
(vv)Other Underwriting Agreements. The Company is not a party to any agreement with an agent or underwriter for any other “at the market” or continuous equity transaction.
(ww)Lending Relationship. Except as disclosed in the Registration Statement and the Prospectus, the Company (i) does not have any material lending or other relationship with the Agent or any bank, lending or other affiliate of the Agent and (ii) does not intend to use any of the proceeds from the sale of the Shares to repay any outstanding debt owed to the Agent or any affiliate of the Agent.