| | |
 | | |
| | Magna Electronics Europe GmbH & Co. OHG Kurfürst-Eppstein-Ring 9 63877 Sailauf, Germany |
aa. rights of the BMW Group based on ownership title or possession,
bb. rights of the BMW Group based on IP Rights, in particular copyright, and rights of use which have been transferred or granted or permissions which have been granted,
cc. statutes and agreements giving rise to duties of confidentiality or bans on exploitation in respect of INNOVIZ, and
dd. rights in respect of personal data (data privacy law).
13.2. | Information Security |
a) INNOVIZ hereby warrants to Magna that the software used or created in connection with performance of the services shall be free of any functionalities presenting a risk to the integrity, confidentiality and availability of the services for which the Parties have contracted, or to other hardware or software or Data, as a result, for example, of functions
aa. which result in undesired export/leakage of Data,
bb. which result in undesired modifications /manipulations of Data or the sequential logic thereof or
cc. which result in undesired insertion of Data or undesired functional extensions.
“Undesired” within the meaning of these requirements is any function which has neither been requested by Magna or BMW nor offered by INNOVIZ with a specific description of the function thereof and the impacts of such function, where Magna or BMW has not accepted this in writing in the individual case.
b) BMW Data must be treated as trade and business secrets of the BMW Group. INNOVIZ must secure BMW Data and its own Data required for its performance of the services in line with the state of art and technology against unauthorized access, modification, destruction and other misuse (“Information Security”). In particular, INNOVIZ shall strictly separate BMW Data from Data of other clients and treat such BMW Data separately and shall implement corresponding protective mechanisms to protect BMW Data from access by other clients. To the extent that the security of BMW Data constitutes a part of INNOVIZ’ services, INNOVIZ shall put all precautions in place in line with the current state-of-the-art and technology in order to be in a position to re-create the Data at any time in a manner which is legally secure and free of Data loss.
c) Depending on the type and the level of protection required for the BMW Data in question, or the significance of INNOVIZ’ services in respect of the BMW Group’s business operations, Magna or BMW may demand that INNOVIZ implement a particular degree of security measures and furnish evidence as prescribed by Magna or BMW regarding an appropriate level of Information Security within the Contractor’s business, in particular by producing appropriate certificates (e.g. ISO/IEC 27001 “Information technology – IT security techniques – Information security management systems - Requirements”) or testing under the VDA model “TISAX” (Trusted Information Security Assessment Exchange).
d) INNOVIZ shall ensure that, in the course of performing the services, it does not deploy any software which might potentially cause damage (e.g. viruses, worms or Trojan horses) for example contained within drivers or firmware supplied together with the Contractor’s Work Results. INNOVIZ must verify this in suitable form and must confirm in writing to Magna upon request that, in undertaking such tests, it has not found any indications of any harmful software.
18