PRIVACY POLICY
Annapurna Suite
Version: 3.2 | Last revision: January 03, 2025
Data Confidentiality and Security Standards
-
Confidential Information. “Confidential Information” means all information regarding
Customer’s and APMT’s business (the “parties”), including, without limitation, technical, marketing,
financial, employee, planning and other confidential or proprietary information, disclosed by a
Customer or APMT, that is clearly identified as confidential or proprietary at the time of disclosure
or that the receiving party knew or should have known, under the circumstances, was considered
confidential or proprietary. Annapurna’s Confidential Information includes information derived from
or concerning the Service, the System or the Documentation. Customer’s Confidential Information
includes the Customer Data.
-
Customer Data (Definition). “Customer Data” means any data, information or information
contained in any database, template or other similar document (a) submitted by Customer or a User
through the Service, (b) provided by Customer or a User to Annapurna as part of the Service, or
(c) supplied to Annapurna by or on behalf of Customer.
-
Personal Information. “Personal Information” means information about or relating to an
identified or identifiable individual that is subject to any Privacy Laws.
-
Privacy Laws. “Privacy Laws” means all applicable federal and provincial legislation and
regulations governing the collection, use and disclosure of Personal Information in the jurisdictions
where Customer has subscribed to use the Service, which may include the Personal Information and
Protection of Electronic Documents Act (Canada) and equivalent provincial, state, federal and
international legislation.
Customer Data (Responsibility). Customer is solely responsible for the Customer Data and will
not provide or transmit any Customer Data or any other information, data or material that: (a) infringes
or violates any intellectual property rights, publicity/privacy rights, law or regulation; or (b) contains
any viruses or programming routines intended to damage, surreptitiously intercept or expropriate any
system, data or personal information. APMT may take remedial action if Customer Data violates this;
however, APMT is under no obligation to review Customer Data for accuracy or potential liability.
Confidential Information
-
Obligations. Each party agrees (a) to hold the other party’s Confidential Information
in strict confidence, (b) to limit access to the other party’s Confidential Information to those of
its employees or agents having a need to know and who are bound by confidentiality obligations at
least as restrictive as those contained herein, and (c) not to use such Confidential Information
for any purpose except as expressly permitted hereunder. Notwithstanding the foregoing, the
receiving party will not be in violation of this with regard to a disclosure that was in response
to a valid order or requirement by a court or other governmental body, provided that the receiving
party gives the other party prior written notice of such disclosure in order to permit the other
party to seek confidential treatment of such information.
-
Exceptions. The restrictions on use and disclosure of Confidential Information set forth
above will not apply to any Confidential Information, or portion thereof, which (a) is or becomes
a part of the public domain through no act or omission of the receiving party, (b) was in the
receiving party’s lawful possession prior to the disclosure, as shown by the receiving party’s
competent written records, (c) is independently developed by the receiving party without reference
to the disclosing party’s Confidential Information, as shown by the receiving party’s competent
written records, or (d) is lawfully disclosed to the receiving party by a third party without
restriction on disclosure.
Data Security
-
Storage. APMT will securely store customer data on its servers. APMT will make all
reasonable efforts to keep customer data confidential and safely stored, accessible only to
registered Customers’ users.
-
Storage and Access After Subscription Termination. APMT will provide access for the user
to download its data for 3 months after the subscription has finished. After 3 months from the
subscription’s termination, users will not be able to access the system or the data. APMT will
securely store the information for 6 months after the subscription termination; after that date,
it will permanently delete all customer information. The customer can request APMT to release the
data before that date. The Customer can request APMT to delete all information stored in its
servers at any point. At the customer’s request, APMT will submit a certificate stating it has
deleted all customer data from its servers.
-
Customer Data Access. APMT will not be able to access customer data uploaded by the
Customers to its servers unless explicitly allowed by the Customer for the provision of the
Services.
-
Disaster Recovery. Information is automatically backed up on a daily basis. Should the
service be interrupted by infrastructure or software failure, a recovery copy of all the customer
information will be made available within 48 hours. Information deletion by the user, given all
the safeguards the system provides, is not considered a disaster APMT can be responsible for and
is outside the scope of the recovery SLA. Notwithstanding, APMT will help the customer recover
lost data to a reasonable effort.
-
Access and Security Guidelines. Subject to any limitations associated with Customer’s
subscription account, APMT may set up user accounts by supplying a unique user identification
name and password (“UserID”) for each User. A User may only access and use the Service with
their specific UserID. Customer is responsible to ensure UserIDs are not shared, and that
Users retain the confidentiality of their UserIDs. Customer is responsible for any and all
activity occurring under the UserIDs associated with Users. Customer will promptly notify
Annapurna of any actual or suspected unauthorized use of the Service. Annapurna may require
that a UserID be replaced at any time.
---- END ----