Last updated: July 21, 2026
This Data Processing Addendum (together with its annexes, this “DPA”) supplements and forms part of the Cara Standard Terms governing the provision by Oyster Technologies, Inc. d/b/a Cara (“Cara”) of its Cloud Service to its Customers (the “Agreement”). This DPA shall be effective as of the Effective Date of the Agreement and replaces and supersedes any data processing addendum entered by the Parties prior to such date. This DPA refers to Cara and Customer, individually, as a “Party” and, collectively, as the “Parties”.
Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. For purposes of this DPA:
“Controller” means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
“Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.
“Data Subject Request” means the request of a Data Subject to exercise rights under Data Protection Laws in respect of Customer Personal Data pertaining to such Data Subject in Cara’s possession or control.
“EEA” means the European Economic Area.
“Personal Data Breach” means a breach of Cara’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Cara’s possession or control.
“Processor” means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of another individual or entity, which may be a Controller or another Processor.
“Restricted Transfer” means a transfer of Customer Personal Data to an importer located (a) where the EU GDPR applies, any country or territory outside the EEA that does not benefit from an applicable adequacy decision from the European Commission described in Article 45 of the GDPR (an “EU Restricted Transfer”); (b) where the UK GDPR applies, any country or territory outside the UK that does not benefit from an applicable adequacy decision from the UK Government (a “UK Restricted Transfer”); or (c) where the FADP applies, any country outside of Switzerland that does not benefit from an adequacy determination by the Swiss Federal Council (a “Swiss Restricted Transfer”), in each case, which would be prohibited without a legal basis under Chapter V of the GDPR or the FADP, as applicable.
“SCCs” means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914, as populated in accordance with Annex 2 (Europe Annex).
“Subprocessor” means any third party engaged directly or indirectly by or on behalf of Cara to Process Customer Personal Data under Cara’s possession or control.
“Supervisory Authority” means (a) in the context of the EEA and the EU GDPR, “supervisory authority” as defined in the EU GDPR; (b) in the context of the UK and the UK GDPR, the UK Information Commissioner’s Office; and (c) in the context of Switzerland and the FADP, the Swiss Federal Data Protection and Information Commissioner.
“UK Transfer Addendum” means the template Addendum B.1.0 issued by the ICO under Section 119A of the Data Protection Act 2018, in force from 21 March 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof (the “UK Mandatory Clauses”).
SCOPE OF THIS DATA PROCESSING ADDENDUM
The Parties acknowledge and agree that Annex 1 (Data Processing Details) to this DPA describes the details of Cara’s Processing of Customer Personal Data (including the respective roles of the Parties relating to such Processing). Annex 2 (Europe Annex) and Annex 3 (California Annex), as applicable, to this DPA apply to Cara’s Processing of Customer Personal Data in accordance with their respective terms. The terms of this DPA apply solely with respect to Cara’s Processing of Customer Personal Data subject to the GDPR, the CCPA or other Data Protection Laws requiring data protection terms to be included in contracts between Customer and its Processors (or as applicable, “Service Providers”, as defined in the CCPA).
PROCESSING OF CUSTOMER PERSONAL DATA
Cara shall Process Customer Personal Data only according to Customer’s instructions or as required by applicable laws (or in the case of Customer Personal Data subject to the GDPR, the laws of the UK or EU, as applicable, to which Cara is subject). Customer instructs Cara to Process Customer Personal Data to provide the Cloud Service and as authorized by the Agreement. The Agreement and Customer’s use of the Cloud Service’s settings and features in accordance with the Agreement are the complete expression of such instructions, and Customer’s additional instructions shall be binding on Cara only pursuant to an amendment to this DPA signed by Cara. Where Cara receives an instruction from Customer that, in Cara’s reasonable opinion, infringes Data Protection Laws, Cara shall notify Customer. Access to Personal Data does not form part of the consideration exchanged between the Parties in respect of the Agreement or any other business dealings.
CARA PERSONNEL
Cara shall ensure that all Cara personnel who access Customer Personal Data are subject to contractual or other legal duties of confidentiality with respect to such Customer Personal Data.
SECURITY
Cara shall implement and maintain technical, organizational, and physical measures designed to protect the confidentiality, integrity, and availability of Customer Personal Data (the “Security Measures”), which measures shall include those described in Annex 4 (Security Measures) and those required by Data Protection Laws. Cara may modify the Security Measures from time to time so long as the modifications do not decrease the overall protection of Customer Personal Data.
DATA SUBJECT REQUESTS
Customer is solely responsible for responding to Data Subject Requests. Considering the nature of the Processing of Customer Personal Data and employing appropriate technical and organizational measures, Cara shall provide Customer with such assistance as Customer may reasonably request in writing to enable Customer to perform its obligations under Data Protection Laws to respond to Data Subject Requests. Cara shall promptly notify Customer if it receives a Data Subject Request and shall advise the Data Subject to submit the request to Customer.
PERSONAL DATA BREACHES
Cara shall notify Customer of a Personal Data Breach without undue delay after becoming aware of the occurrence thereof. If Customer determines that notice of a Personal Data Breach must be given to any Supervisory Authority or other governmental authority, any Data Subject, the public or others in a manner that directly or indirectly refers to or identifies Cara, where permitted by applicable laws, Customer shall notify Cara prior to giving such notice and in good faith consult with Cara regarding such notice and consider any clarifications or corrections Cara may reasonably recommend or request to any such notification. Cara’s notification of or response to a Personal Data Breach shall not be construed as Cara’s acknowledgement of any fault or liability with respect to the Personal Data Breach.
SUBPROCESSING
Authorization; Current Subprocessors. Customer generally authorizes Cara to engage Subprocessors in accordance with this Section 8, including the Subprocessors listed as of the date of this DPA or other such web page as Cara may provide to Customer from time to time (“Subprocessor Page”).
Requirements. Cara shall enter into a written contract with each Subprocessor imposing on such Subprocessor data protection obligations at least as protective as those in this DPA with respect to Customer Personal Data to the extent applicable to the nature of the services such Subprocessor provides. Cara shall be liable for all Processing of Customer Personal Data delegated to the Subprocessor and its actions and omissions related thereto.
New Subprocessors. When Cara engages any new Subprocessor not listed on the Subprocessor Page as of the Effective Date, Cara shall notify Customer of the engagement (including the name, location, and function of the Subprocessor) by updating the Subprocessor Page or by other written means at least 15 days before such Subprocessor Processes Customer Personal Data. If Customer objects to such engagement in a written notice to Cara within 15 days after being notified of the engagement on reasonable grounds relating to the protection of Personal Data, Customer and Cara shall work together in good faith to resolve such objection in a mutually acceptable manner. If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Cloud Service by providing written notice to Cara and paying Cara for all amounts due and owing under the Agreement as of the date of such termination.
COMPLIANCE ASSISTANCE; AUDITS
Compliance assistance. Taking into account the nature of the Processing and the information available to Cara, Cara shall provide such information and assistance as Customer may reasonably request to enable Customer to perform its obligations under Data Protection Laws in relation to Cara’s Processing of Customer Personal Data, including in relation to (i) the security of Customer Personal Data, (ii) the investigation and reporting of Personal Data Breaches, (iii) the demonstration of Cara’s compliance with this DPA, and (iv) the performance of any data protection assessments and consultations with Supervisory Authorities or other government authorities regarding such assessments in relation to Cara’s Processing of Customer Personal Data, including those required under Articles 35 and 36 of the GDPR.
Information and audits. Cara shall cooperate with audits (including inspections) of Cara’s technical and organizational measures performed to verify compliance with Customer’s obligations under Data Protection Laws and Cara’s compliance with this DPA, provided that such audits shall be performed (i) at Customer’s sole cost and expense, (ii) by Customer (or a qualified and independent third party auditor appointed by Customer) in accordance with a recognized audit control standard or framework, (iii) subject to a non-disclosure agreement acceptable to Cara in respect of information made available to audit participants, (iv) during normal business hours, (v) no more than once in any calendar year during the term of the Agreement unless Customer is required to perform the audit under Data Protection Laws, (vi) in accordance with Cara’s safety, security or other relevant policies, and (vii) without unreasonably interfering with Cara’s business activities. Customer shall not conduct any scans or technical or operational testing of Cara’s applications, websites, Cloud Service, networks, or systems without Cara’s prior approval. Customer shall promptly provide Cara with a copy of any report created by an independent auditor engaged by Customer in respect of such an audit. This Section 9 shall not be construed to require Cara to violate a duty of confidentiality to any third party.
Audit reports. If the controls or measures to be assessed in the requested audit are assessed in an audit performed by a qualified and independent third party auditor pursuant to a recognized audit control standard or framework (e.g., SOC 2 Type 2, NIST, ISO 27001) within twelve (12) months of Customer’s audit request, and Cara has confirmed in writing that there have been no known material changes to the controls audited and covered by such audit, Customer agrees to accept the auditor’s report regarding such audit (“Audit Report”) in lieu of requiring an audit of such controls or measures. Such Audit Report and any other information obtained by Customer in connection with an audit under this Section 9 shall constitute confidential information of Cara, which Customer shall use only for the purposes of confirming compliance with the requirements of this DPA or performing Customer’s obligations under Data Protection Laws. Cara shall provide Customer with its Audit Reports upon Customer’s written request.
RETURN AND DELETION AT EXPIRATION OF TERM
If Customer wishes to retain any Customer Personal Data in Cara’s possession or control after the end of the term of the Agreement, Customer will use any self-service tools available in the Cloud Service to retrieve such data on its own, and with respect to any such data that Customer cannot retrieve with such tools, Customer may instruct Cara to return such data during such term. Customer instructs Cara to delete all remaining Customer Personal Data in Cara’s possession or control at the end of such term. Cara will comply with this instruction as soon as reasonably practicable and within a maximum period of 180 days. Notwithstanding the foregoing, Cara may retain Customer Personal Data where required by law (or in the case of Customer Personal Data subject to the GDPR, the laws of the UK or European Union, as applicable), provided that Cara shall (a) maintain the confidentiality of all such Customer Personal Data and (b) Process the Customer Personal Data only as necessary for the purpose and duration specified in the applicable law requiring such retention.
CUSTOMER RESPONSIBILITIES
Security. Customer is solely responsible for its use of the Cloud Service, including (i) making appropriate use of the Cloud Service to maintain a level of security appropriate to the risk posed to Customer Data; (ii) securing the account authentication credentials, systems and devices that Customer and its personnel use to access the Cloud Service; and (iii) regularly backing up Customer Data. Customer is responsible for all activity through Customer’s Cloud Service account accessed through the credentials used by Customer or its personnel to access the account, whether or not such activity was authorized.
Legal basis. Customer will not instruct Cara to Process Customer Data in violation of Data Protection Laws. Cara has no obligation to monitor the compliance of Customer’s use of the Service with Data Protection Laws. Customer shall ensure (and is solely responsible for ensuring) that (i) there is a valid legal basis for Cara to Process Customer Personal Data as contemplated by the Agreement for purposes of Data Protection Laws and (ii) all notices have been given to, and all consents and permissions have been obtained from, Data Subjects and others as are required, including under Data Protection Laws, for Cara to Process Customer Personal Data as contemplated by the Agreement.
Additional assistance. If Customer requests cooperation, information or assistance pursuant to Sections 6, 9, or 10 of this DPA beyond Cara’s provision of the self-service features available to Customer in the Cloud Service that Customer can use to obtain the requested cooperation, information or assistance, then Customer shall reimburse Cara for any costs and expenses reasonably incurred by Cara in the course of responding to such requests and Cara reserves the right to charge its applicable fees for professional services required to fulfill such requests.
PRECEDENCE; MISCELLANEOUS
In the event of any conflict or inconsistency between (a) this DPA and the Agreement, this DPA shall prevail or (b) any SCCs entered into pursuant to Annex 2 (Europe Annex) and any other provision of the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply. References to “including” mean “including, without limitation”.
Annex 1 – Data Processing Details
CUSTOMER / ‘DATA EXPORTER’ DETAILS
Name: As provided in the Order Form.
Contact details for data protection: As provided in the Order Form.
Customer Activities: As described on Customer’s website hosted at the domain identified in the Customer contact email provided in the Order Form.
Role: Controller (or if Customer uses the Cloud Service on behalf of a Controller, Processor).
CARA / ‘DATA IMPORTER’ DETAILS
Name: Oyster Technologies, Inc.
Contact details for data protection: support@getcara.ai
Cara Activities: Cara offers an AI-powered connective operating system that helps insurance agencies and brokerages optimize operational workflows.
Role: Processor (or if Customer uses the Cloud Service on behalf of a Controller, subprocessor).
DETAILS OF PROCESSING
Categories of Data Subjects and Personal Data. Customer acknowledges that Cara does not directly or indirectly control or determine the nature of the Customer Personal Data. Accordingly, Customer represents and warrants that the categories of Data Subjects and Personal Data are as follows:
Categories of Data Subjects:
Users
Customer’s customers and prospective customers
Customer’s employees, contractors, job applicants and other personnel
Customer’s business contacts
Categories of Personal Data:
Contact data (e.g., name, email address, phone number, mailing address)
Demographic information (e.g., date of birth, gender)
Household information (e.g., information about dependents)
Professional and education information (e.g., employer names and contact, job titles, job history, education history)
Commercial information (e.g., products or services purchased or considered)
Residential information (e.g., homeowner status, property where you live)
Driving information (e.g., driving history, license status)
Communications information
Unique identifiers
Special Categories of Personal Data (as defined in GDPR) and associated additional restrictions/safeguards: Customer may submit special categories of data to the Services as permitted in the Agreement. Such data shall be Processed in accordance with Section 5 of this DPA (Security).
Frequency of transfer: Continuous.
Nature of the Processing: Processing operations required to provide the Cloud Service in accordance with the Agreement.
Purpose of the Processing: Provide the Cloud Service, as more particularly described in the Agreement, and carry out Customer instructions as described in this DPA.
Duration of Processing / Retention Period: Concurrent with term of the Agreement and then thereafter pursuant to Section 10 of the DPA.
Transfers to Subprocessors: As described in the Subprocessor Page for the purposes described therein.
Annex 2 – Europe Annex
This Annex 2 (Europe Annex) applies only to the extent required to establish a valid legal basis under Chapter V of the GDPR and/or the FADP (as applicable) in respect of a Restricted Transfer of Customer Personal Data from Customer to Cara where no other such legal basis applies.
EU RESTRICTED TRANSFERS
Incorporation of SCCs. In respect of any EU Restricted Transfer from Customer to Cara, the Parties shall comply with their respective obligations under the SCCs, which are hereby deemed to be (i) populated in accordance with this Paragraph 1 and (ii) entered into by the Parties and incorporated by reference into this DPA.
Population of SCCs. In respect of any EU Restricted Transfer from Customer to Cara:
Signature of the SCCs. Each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs and those SCCs are entered into by and between the Parties as of the later of (A) the Effective Date of the Agreement or (B) the date of the first EU Restricted Transfer to which they apply.
Modules. With respect to the Processing of Customer Personal Data involving an EU Restricted Transfer or UK Restricted Transfer, Module 2 (Controller to Processor) of the SCCs applies where Customer is a Controller and Cara is a Processor, and Module 3 (Processor to Processor) of the SCCs applies where Customer is a Processor (on behalf of a third-party Controller), and Cara is a Processor.
Body of the SCCs. For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof:
The optional ‘Docking Clause’ in Clause 7 does not apply.
In Clause 9, Option 2 applies. The minimum time for advance notice of the addition or replacement of Subprocessors shall be as specified in Section 8 of the DPA and the list of Subprocessors already authorized by the data exporter shall be the list on the Subprocessor Page as of the effective date of the DPA. Option 1 and Annex III to the Appendix to the SCCs do not apply.
In Clause 11, the optional language does not apply.
In Clause 13, all square brackets are removed with the text remaining.
In Clause 17, Option 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer.
For purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly.
Annexes to the Appendix to the SCCs
Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with Customer being the ‘data exporter’ and Cara being the ‘data importer’.
Part C of Annex I to the Appendix to the SCCs is populated to provide that the competent supervisory authority shall be (1) where Customer is established in an EU Member State, the supervisory authority of that EU Member State; (2) where Customer is not established in an EU Member State but is subject to the GDPR under Article 3(2) and has appointed an EU representative under Article 27 of the GDPR, the supervisory authority of the EU Member State in which Customer’s EU representative is based; or (3) where Customer is not established in an EU Member State but is subject to the GDPR under Article 3(2) and has not appointed an EU representative under Article 27 of the GDPR, the supervisory authority of one of the EU Member States in which Data Subjects whose Personal Data is transferred in the Restricted Transfer in relation to the offering of goods or services to them, or whose behavior is monitored, are located, which supervisory authority must be confirmed in a written notice from Customer to Cara.
Annex II to the Appendix to the SCCs is populated to incorporate the description of the Security Measures in Section 5 of the DPA and Cara’s obligations under Sections 6 and 7 of the DPA.
Operational Clarifications
When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer shall not provide or otherwise make available, and shall take all appropriate steps to protect, Cara’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information.
For the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Cara to notify any third-party Controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer.
For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subjects if and as required.
The terms and conditions of Section 8 of the DPA apply in relation to Cara’s appointment and use of Subprocessors under the SCCs. Any approval by Customer of Cara’s appointment of a Subprocessor that is given expressly or deemed given pursuant to Section 8 of the DPA constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Subprocessors as required under Clause 8.8 of the SCCs.
The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to the relevant terms and conditions detailed in Section 9 of the DPA.
Certification of deletion of Customer Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer’s written request.
Liability to Data Subjects. Nothing in the Agreement shall limit either party’s liability to Data Subjects under the third party beneficiary provisions of the SCCs.
UK RESTRICTED TRANSFERS
Incorporation of SCCs; UK Transfer Addendum. In respect of any UK Restricted Transfer from Customer to Cara, the Parties shall be bound by the SCCs as set forth in Paragraph 1 and such SCCs are hereby deemed to be (i) modified to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with this Paragraph 2 and (ii) entered by the Parties and incorporated by reference into this DPA. As permitted by Section 17 of the UK Mandatory Clauses, the Parties agree that the manner of the presentation of the information included in the UK Transfer Addendum as set out in this Paragraph 2 shall not operate or be construed to reduce the Appropriate Safeguards (as defined in the Mandatory Clauses).
Population of UK Transfer Addendum. In respect of any UK Restricted Transfer from Customer to Cara:
With respect to Part 1 of the UK Transfer Addendum, as permitted by Section 17 thereof, (A) Tables 1, 2 and 3 to the UK Transfer Addendum are populated with the corresponding details set out in Annex 1 (Data Processing Details) to the DPA, subject to the variations effected by the UK Mandatory Clauses described below and (B) Table 4 to the UK Transfer Addendum is populated by the box labelled ‘Data Importer’ being ticked.
With respect to Part 2 to the UK Transfer Addendum, the Parties shall be bound by the UK Mandatory Clauses thereof.
SWISS RESTRICTED TRANSFERS
Swiss Restricted Transfers. In respect of any Swiss Restricted Transfer from Customer to Cara, the Parties shall be bound by the SCCs as set forth in Paragraph 1 and such SCCs are hereby deemed to be (i) modified to address the requirements of the FADP in accordance with this Paragraph 3 and (ii) entered into by the Parties and incorporated by reference into this DPA.
Population of SCCs. In respect of any Swiss Restricted Transfer from Customer to Cara:
In Clause 13, the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner.
In Clause 17 (Option 1), the SCCs shall be governed by the laws of Switzerland.
In Clause 18(b), disputes shall be resolved before the courts of Switzerland.
The term “Member State” must not be interpreted in such a way as to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence in accordance with Clause 18(c).
All references to the EU GDPR in this DPA are also deemed to refer to the FADP.
DATA PRIVACY FRAMEWORK
For clarity, a transfer of Customer Personal Data from the EU, UK or Switzerland to Cara in the United States shall not constitute a Restricted Transfer at any time that Cara maintains an active certification to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework, as applicable (collectively, the “DPF”), and certification to the DPF remains a legal basis for transfer of Personal Data to the United States under the GDPR or FADP, as applicable.
Annex 3 – California Annex
This Annex 3 (California Annex) applies only to Cara’s Processing of Customer Personal Data subject to the CCPA.
Capitalized terms used in this California Annex but not defined in the DPA shall have the meanings given in the CCPA. As used in this California Annex, “Personal Information” means Customer Personal Data that constitutes “personal information” under the CCPA.
It is the Parties’ intent that Cara is a Service Provider with respect to its Processing of Personal Information. Cara (a) acknowledges that Personal Information is disclosed by Customer only for limited and specified purposes described in the Agreement; (b) shall comply with applicable obligations under the CCPA and shall provide the same level of privacy protection to Personal Information as is required by the CCPA; (c) agrees that Customer has the right to take reasonable and appropriate steps under Section 9 of the DPA to help to ensure that Cara’s use of Personal Information is consistent with Customer’s obligations under the CCPA; (d) shall notify Customer in writing of any determination made by Cara that it can no longer meet its obligations under the CCPA; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.
Cara shall not (a) Sell or Share Personal Information; (b) retain, use, or disclose any Personal Information for any purpose other than for the Business Purposes specified in the Agreement, including retaining, using, or disclosing Personal Information for a Commercial Purpose other than the Business Purpose specified in the Agreement, or as otherwise permitted by CCPA; (c) retain, use or disclose Personal Information outside of the direct business relationship between Cara and Customer; or (d) combine Personal Information received pursuant to the Agreement with Personal Information (i) received from or on behalf of another person, or (ii) collected from Cara’s own interaction with any Consumer to whom such Personal Information pertains. Cara hereby certifies that it understands its obligations under this paragraph and shall comply with them.
Giving Customer notice of Subprocessor engagements in accordance with Section 8 of the DPA shall satisfy Cara’s obligation under the CCPA to give notice of such engagements.
The Parties acknowledge that Cara’s Processing of Personal Information authorized by Customer’s instructions described in this DPA is integral to the Cloud Service and the Parties’ business relationship.
Annex 4 – Security Measures
Cara will implement and maintain the Security Measures with respect to Customer Personal Data as set out in this Annex 4:
Organizational management and dedicated staff responsible for the development, implementation, and maintenance of Cara’s information security program.
Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Cara’s organization, monitoring and maintaining compliance with Cara’s policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
Data security controls which include at a minimum logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available and industry standard encryption technologies for Customer Personal Data.
Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions.
Password controls designed to manage and control password strength, expiration and usage.
System audit or event logging and related monitoring procedures to proactively record user access and system activity.
Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Cara’s possession.
Procedures and tracking mechanisms designed to test, approve, and monitor all material changes to Cara’s technology and information assets.
Incident management procedures designed to allow Cara to investigate, respond to, mitigate, and notify of events related to Cara’s technology and information assets.
Vulnerability assessment and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disaster.
