Use of the Card 1. The Cardmember must sign the Card in ink, using a ball point pen, as soon as he or she receives it; the Cardmember must also safeguard the Card and preserve any PIN in extreme secrecy and keep it separate from his or her Card. The Cardmember must not use the Card after the expiration of the validity period embossed on it, and not use the Card after it has been damaged, withdrawn or cancelled. 2. Although the Cardmember has the right to use the Card, the Card shall at all times remain the property of AEME. The Cardmember must surrender the Card immediately upon any request by AEME, any Service Establishment or any other representative of AEME, based on AEME's instructions. A Service Establishment or any other representative of AEME may at its discretion, and after instructions by AEME, withdraw, hold and keep the Card on behalf of AEME. 3. The Cardmember is the only person authorized to use the Card for Transactions including Cash Withdrawals, identification or any other purpose. The Cardmember must not allow any other person to use the Card or the PIN. The Cardmember must safeguard the Card from misuse by retaining the Card under his or her personal control at all times. 4. The Card is issued to the Cardmember solely for the purposes of Transactions and Cash Withdrawals on behalf of the Company. 5. If the Cardmember uses the Card to buy goods or services from a Service Establishment on a frequent or recurring basis (e.g. subscription to periodicals, TV channels, and the like) ("Recurring Charges") or if the Cardmember uses the Card to buy goods or services on installments or on a premium basis (e.g. insurance) the Cardmember authorizes AEME to pay all such Recurring Charges or periodical premiums or installments on his or her behalf at the request of the Service Establishment, and the Company undertakes to repay AEME accordingly. The Cardmember must inform the Service Establishment and AEME in writing if the Cardmember wishes to stop any such periodical payments. AEME shall not be responsible for any breach, cancellation or termination of any legal arrangement or relationship (e.g. insurance policy) resulting from AEME's inability to pay the said Charges because the Cardmember's Account is in overdue status. AEME shall not be liable for any damages of any nature if AEME fails to pay or delays the payment of any Charges, installments or premiums because of any technical failure, error or for any reason beyond AEME's reasonable control. 6. Owners of Service Establishments who are Cardmembers are not allowed to use their Cards in their own Service Establishments. The Cardmember is not allowed to utilize the Card to fund any part of, or to meet the working capital requirements of his or her business. 7. The Company is solely liable for all amounts due on the Account and for all Charges incurred on the Card issued to the Cardmember. 8. The Cardmember is not entitled to use the Card to withdraw or extract cash in Service Establishments, and shall only use the Card to purchase goods or services. 9. The Cardmember shall not use the Card as payment for any illegal or unlawful purchases or services and is responsible for any use that is in violation of any local or other laws and regulations. The Cardmember further agrees to indemnify AEME for any action whatsoever that may arise as a result of such Transactions. 10. The Cardmember expressly authorizes AEME to use the information provided by the Cardmember for AEME's targeted promotional activities including without limitation, promotional activities conducted in conjunction with third parties selected by AEME, for third party researches and surveys, in accordance with the limitations of the applicable laws. 11. The Cardmember agrees to follow the Card activation procedures laid down by AEME from time to time and shall also be subject to any identity checks and verifications by AEME and or any third parties (e.g. credit bureaus, government agencies, Service Establishments, etc). 12. All Charges will be debited to the Account in the billing currency (i.e. USD). Any Transactions that are effected in currencies other than the billing currency will be debited to the Account after conversion as set forth in Clause 4.
Infrastructure Vulnerability Scanning Supplier will scan its internal environments (e.g., servers, network devices, etc.) related to Deliverables monthly and external environments related to Deliverables weekly. Supplier will have a defined process to address any findings but will ensure that any high-risk vulnerabilities are addressed within 30 days.
Use of sub-processors 1. The data processor shall meet the requirements specified in Article 28(2) and (4) GDPR in order to engage another processor (a sub-processor). 2. The data processor shall therefore not engage another processor (sub-processor) for the fulfilment of the Clauses without the prior general notification of the data controller. 3. The data processor has the data controller’s general authorisation for the engagement of sub-proces- sors. The data processor shall inform the data controller of any intended changes concerning the addi- tion or replacement of sub-processors at least 14 days in advance, thereby giving the data controller the opportunity to object to such changes prior to the engagement of the concerned sub-processor(s). Longer time periods of prior notice for specific sub-processing services can be provided in Appendix B. The list of sub-processors already authorised by the data controller can be found in Appendix B. 4. Where the data processor engages a sub-processor for carrying out specific processing activities on behalf of the data controller, the same data protection obligations as set out in the Clauses shall be imposed on that sub-processor by way of a contract or other legal act under EU or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the Clauses and the GDPR. The data processor shall therefore be responsible for requiring that the sub-processor at least complies with the obligations to which the data processor is subject pursuant to the Clauses and the GDPR. 5. A copy of such a sub-processor agreement and subsequent amendments shall – at the data controller’s request – be submitted to the data controller, thereby giving the data controller the opportunity to ensure that the same data protection obligations as set out in the Clauses are imposed on the sub-processor. Clauses on business related issues that do not affect the legal data protection content of the sub-pro- cessor agreement, shall not require submission to the data controller. 6. The data processor shall agree a third-party beneficiary clause with the sub-processor where – in the event of bankruptcy of the data processor – the data controller shall be a third-party beneficiary to the sub-processor agreement and shall have the right to enforce the agreement against the sub-processor engaged by the data processor, e.g., enabling the data controller to instruct the sub-processor to delete or return the personal data. 7. If the sub-processor does not fulfil his data protection obligations, the data processor shall remain fully liable to the data controller as regards the fulfilment of the obligations of the sub-processor. This does not affect the rights of the data subjects under the GDPR – in particular those foreseen in Articles 79 and 82 GDPR – against the data controller and the data processor, including the sub-processor.