Skip to Content

Data Security Guidelines

These Data Security Guidelines (“Security Guidelines”) set forth the duties and obligations of Provider with respect to the security of Personal Information of Company Clients. In the event of any inconsistencies between the Security Guidelines and the Agreement (defined below), the parties agree that the Security Guidelines will supersede and prevail. Capitalized terms not defined herein shall have the meaning ascribed to them in the Agreement.

1. Definitions.

a. “Agreement” means the Agreement for the Services between the Provider and Company incorporating Provider’s Privacy Notice at https://greatgray.com/privacy-policy/ to which these Security Guidelines are referenced and made a part thereof.

b. “Applicable Laws” means federal, state and international privacy, data protection and information security-related laws, rules and regulations applicable to the Services and to Personal Information, including without limitation the Gramm-Leach- Bliley Act (1 5 U. S. C. § § 6801 et seq.) and implementing regulations, state data security regulations, and other privacy laws applicable to financial institutions and their service providers.

c. “Company Client” means Company’s shareholders, employees, depositors, customers, clients or other end users.

d. “Provider” refers collectively to Great Gray Group, LLC, and its affiliates that provide the Services pursuant to this Agreement, including but not limited to Retirement Plan Advisory Group, LLC (“RPAG”)

e. “Personal Information” means information provided to Provider in connection with Provider’s obligations to provide the Services under the Agreement that (i) could reasonably identify the individual to whom such information pertains, such as name, address and/or telephone number or (ii) can be used to authenticate that individual, such as passwords, unique identification numbers or answers to security questions or (iii) is protected under Applicable Laws. For the avoidance of doubt, Personal Information does not include aggregate, anonymized data derived from an identified or identifiable individual.

f. “Security Incident” means a confirmed, unsecured, unlawful access to, acquisition of, disclosure of, loss of, corruption of, or use of Personal Information of Company Clients which poses a significant risk of financial, reputational or other harm to the affected User or Company, or any other breach of Provider’s Information Security Program that compromises the security, confidentiality, or integrity of Personal Information of Company Clients.

g. “Services” means any services and/or products provided by Provider in accordance with the Agreement.

2. Regulatory Compliance and Acknowledgements. Provider acknowledges that it is familiar with the Gramm-Leach-Bliley Act (1 5 U. S. C. § § 6801 et seq.) and the rules and regulations promulgated thereunder, including without limitation the Federal Trade Commission’s Privacy of Consumer Financial Information Rule and Safeguards Rule (1 6 C. F. R. Part 3 1 4), and understands that Company may be subject to GLBA as a financial institution. Provider agrees to comply with all applicable requirements of GLBA in its role as a service provider to Company. Provider further acknowledges that Company may be subject to regulatory examination and oversight by federal and state financial services regulators and agrees to cooperate with any such examinations to the extent they relate to Provider’s handling of Personal Information or performance of the Services.

3. Information Security Program. At all times while providing the Services and/or while in possession of any of Company’s Confidential Information, including any Personal Information of Company Clients, Provider shall have in place and maintain an Information Security Program that meets Industry Standards. Provider’s Information Security Program shall include policies and/or procedures for responding to information security events as well as appropriate administrative, technical, and physical safeguards which are reasonably designed to protect the security, confidentiality, and integrity of Confidential Information stored by Provider. As used herein, “Information Security Program” means the collection of written policies, standards, procedures, practices, and controls implemented by Provider to protect the security, confidentiality, integrity, and availability of Confidential Information. As used herein, “Industry Standard(s)” means the then-current version of, as applicable: (i) the National Institute of Standards and Technology (“NIST”) publications related to privacy, information security, and cybersecurity (including, without limitation, NIST SP 800 Series publications and the NIST Privacy Framework); (ii) International Organization for Standardization and International Electrotechnical Commission (“ISO/IEC”) 27001 and related guidance and standards; or (iii) any substantially similar and related standards or guidance which are regularly referenced or relied upon by financial services and technology industries for privacy, information security, or cybersecurity controls, policies, and procedures designed to safeguard data. Provider’s Information Security Program shall include appropriate administrative, technical, and physical safeguards which are reasonably designed to protect the security, confidentiality, and integrity of Confidential Information stored by Provider.

4. Security Questionnaire. At Company’s request, at any time during the term of the Agreement, Provider agrees to certify in writing its compliance with Information Security Program requirements (including answering questionnaires provided by Company regarding Provider’s Information Security Program) and must notify Company promptly in writing if at any time Provider determines it cannot meet its obligations stated herein.

5. Security Incident Response. In the event of a Security Incident, Provider shall (i) investigate the Security Incident, identify the impact of the Security Incident and take commercially reasonable actions to mitigate the effects of any such Security Incident, (ii) notify Company as soon as possible, but no later than seventy two (72) hours after becoming aware of the Security Incident, subject to applicable confidentiality obligations and to the extent allowed and/or required by and not prohibited by Applicable Laws or law enforcement. Except to the extent prohibited by Applicable Laws or law enforcement, Provider shall, upon Company’s written request and to the extent available, provide Company with a description of the Security Incident and the type of data that was the subject of the Security Incident.

6. Security Audit. Upon written request by Company, which request shall be no more frequently than once per twelve (12) month period, Provider’s data security measures may be reviewed by Company through an informal audit of policies and procedures or through an independent auditor’s inspection of security methods used within Provider’s infrastructure, storage, and other physical security, any such audit to be at Customer’s sole expense and subject to a mutually agreeable confidentiality agreement and at mutually agreeable timing, or, alternatively, Provider may provide Company with a copy of any third party audit that Provider may have commissioned.

7. Data Subject Rights and Cooperation. Provider agrees to cooperate with Company, both during and after the term of the Agreement, in connection with any proceeding or request to track, delete, process or transfer data under or in compliance with any data protection, data security or privacy law, including any exercise of a “right to be forgotten.”