# Landis Technologies Documentation

Select a link below:

* [Landis Contact Center](https://cc.docs.landis.cloud)
* [Landis Attendant Console](https://ac.docs.landis.cloud)


# Legal


# Privacy

## Landis Technologies Privacy Notice

### Legal information

At Landis Technologies LLC (“Landis” or “we” or “us”), we care about privacy, security and transparency; these are core tenets in our company’s mission. Toward that, this privacy notice tells you what to expect when Landis collects personal information about you, including:

•       How Landis collects data;

•       Understanding who controls your data;

•       Landis’s lawful basis for processing your data;

•       Understanding Landis services;

•       Information sharing and transborder flows;

•       Security, compliance and certification assurance;

•       Your data protection rights;

•       Special information for Residents of California, USA

•       Data retention;

•       Our Commitment to Data Protection and

•       Future changes to this Privacy notice.

Landis Technologies LLC has a registered address at 1120 Division Hwy, Ephrata, PA 17522, United States. The main website for Landis is <https://landistechnologies.com/>

This privacy notice is effective as of September 2025.

&#x20;

### How Landis collects data.

One of the purposes of this Privacy notice is to explain how we collect and process personal data. The primary ways we collect information are as follows: (a) by visiting one of our websites; (b) by subscribing to our service purchased by your Employer or Business from Landis

Please be informed that this website is not intended for children, defined as age 15 and under; we absolutely do not knowingly collect data from children and will immediately delete it if discovered.

We encourage you to read this Privacy notice. It has been written to ensure you understand how we collect information, how it is safeguarded, what is collected, how it is processed, where it is processed, with whom we may share it, and your rights under the law.

&#x20;

&#x20;

### Understanding who controls your data.

When you subscribe to Landis services as a Named User, we act as a Data Processor (“Processor”) under the instructions of the Data Controller. In this instance, all future requests or exercises of your rights must be made to the Controller.

When the Landis service is used in the context of US healthcare, a Business Associate Agreement between Landis and the Customer/Partner is required. We use appropriate safeguards to prevent the use or disclosure of ePHI other than as provided for in the agreement. We use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that is created, received, maintained, or transmitted via the service on behalf of the subscribed Covered Entity or Business Associate.

When you share information with us directly by visiting our website, Landis acts as a Data Controller (“Controller”) according to the definitions in Article 4 of the GDPR. This Privacy notice applies when we are acting as the Controller with respect to the personal data we process about you. In other words, where we determine the purpose and the means of the processing, we are identified as the Controller and we are responsible for controlling and safeguarding your personal data.

Toward that, we have assigned a Privacy Officer to superintend all aspects of this Privacy notice, ensuring your questions are answered and your rights are respected. Whenever you have questions, you should contact the Privacy Officer via one of the venues below:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

Email:<compliance@landistechnologies.com>

### Landis’s lawful basis for processing your data.

Landis will only process your data according to the allowance permitted by law. In most instances, we will only use your data in the following situations:

* when you provide us with your consent to process your personal data which may be revoked by you at any time and for any reason;
* when it may be necessary for our legitimate interest;
* when we may need to respond to a legal requirement or regulatory action; and
* where we need to fulfil our obligation to provide services when you subscribe to our services.

In the following table, we describe ways your personal information may be used; each of these uses are tied to a legal basis for processing. Further, we have also outlined wherever we have a legitimate interest to process your data where appropriate.

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Processing Activity</td><td valign="top">Personal Data</td><td valign="top">Lawful Basis</td></tr><tr><td valign="top">Requesting information and relationship management including emails to us, requests for marketing information, enquiries about services, responding to feedback, notifying you about changes to our terms and conditions, notifying you about changes to our Privacy notice, sending you communication through our newsletters and news bulletins, asking you to update your contact information, communicating with you about our service.</td><td valign="top">Identity data, contact data, communication data, marketing preferences.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. (c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations). (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.</td></tr><tr><td valign="top">Subscribing to Landis services.</td><td valign="top">Name, email address, regional settings, call detail records, call participants to scheduled conferences, media streams and recordings, connection history, technical information about your device hardware and operating system, call diagnostics, last login and operating system, last active and connected date (O365), user ID, time zone, administrative flags, localisation.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Service desk support for the Landis service.</td><td valign="top">If working with our service desk to troubleshoot an issue, we may also gather information about the type of computer systems you use, including associated devices such as microphones and video cameras as these are relevant to the services offered by Landis. The information may also include your IP address, operating system, browser type, language preferences, and other relevant details to help Landis ensure your service is working correctly.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Website analytics.</td><td valign="top">Please be informed that we use a third-party analytics service called Google Analytics to collect, analyze and tally metrics regarding website visits. Analytics help us to determine many things, including the quantity of visitors over time, the geographic location from which visitors arrive, timeframes of high and low usage, the sites most frequented, the pages most frequented, and other helpful data. The Company processes data in ways to ensure individual identity is not stored, only anonymous metrics. Furthermore, it is forbidden for Google to determine, or attempt to determine, the identity of individuals visiting our websites, and this anonymity is inherited by Landis.</td><td valign="top">Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</td></tr><tr><td valign="top">Recruitment process and employment in Landis.</td><td valign="top">Personal data including demographics, contact information, grades, certifications, CVs, general data, tests and other government issued identity documents.</td><td valign="top"><p>Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</p><p>(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests</p></td></tr></tbody></table>

&#x20;

#### Automated decision making and profiling

Landis reserves the right to use AI (Artificial Intelligence) and non-AI based computational logic to automate its operations and shall provide just in time privacy notices where relevant. When such solely automated decisions significantly impact the rights of individuals concerned, we shall provide notice and opportunity to object to such processing.

Profiling is undertaken using website analytics in pursuance of our legitimate interests and as outlined in the above table in this section ‘Landis’s lawful basis for processing your data’.

### Understanding Landis services.

This section applies to users of Landis services. If you only use the Landis public website, this section does not apply to you.

Landis services are driven by an Internet-based communication platform designed to enable business users to communicate using voice calls. The person adding you for the first time to an organisation will provide certain information about you for provisioning, such as your name, company name and work email address.

Wherever possible, the media associated with all Landis originating or terminating audio communications (“calls”) is encrypted. Calls are recorded and saved using Landis’s recording services. Recordings saved using Landis’s recording services products cannot, under any circumstances, be accessed by Landis employees without your organization’s written permission. Where you have given us your consent, we may monitor call metrics to investigate bugs and service issues. Call records will not be made available to anyone outside of Landis without the prior consent of the organisation whose Landis services account was used to originate the calls. Landis reserves the right to anonymize and save your data for any research or statistical purposes.

&#x20;

The Type of Personal Data we collect to provide our MS Teams related services include

·         Named Users Data: Full Name, Email Address, IP Address, User Role

·         Communications Data: The Call Participant Data which includes Name and Email address of the Named Users and the individuals who either receive or make calls to them. The Call Logs Data which include Microsoft Unique Identifier and call metrics. The Audit Logs generated by the Services which capture the user activities, IP address for support and tracking purposes.

·         Landis Policy Call Recording for Teams: Audio streams covering both ends of the call and Speech-to-text conversion of Named Users alone (for training and quality assurance purpose)

·         Landis Attendant Console AI Prompts: AI prompts created based on the call transcripts to aid follow up activities.

&#x20;

### Information sharing and transborder flows.

Landis respects your right to privacy and we do not use or share your personal information in any other way beyond what has been written in this Privacy notice. For instance, we do not sell your information to anyone, including but not limited to third parties for their own marketing use.

As a Data Processor, Landis is acting under the instructions of the Data Controller and may share your data with the Controller in support of your service.

We will inform you or your Data Controller if we are required to share your information under any of the following circumstances: (i) to the extent that we are required to do so by applicable law, by a governmental body or by a law enforcement agency, or for crime prevention purposes; (ii) in connection with any legal proceedings (including prospective legal proceedings); (iii) in order to establish or defend our legal rights; (iv) in the event that we buy or sell any business or assets, in which case we may disclose your personal data to the prospective sellers or buyer of such business or assets; or (v) if a third party acquires all (or substantially all) of our business and/or assets, we may disclose your personal information to that third party in connection with the acquisition.

A list of the service subprocessors of Landis Services are provided below:

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Sub-processor</td><td valign="top">Purpose of Processing Activity</td><td valign="top">Location of Processing</td><td valign="top">Link to Privacy Policy and DPA</td></tr><tr><td valign="top"><p>Microsoft Corporation</p><p> </p><p>920 Fourth Avenue, Suite 2900, Seattle, Washington 95104, US</p><p> </p></td><td valign="top"><p>Azure: Hosting provider</p><p> </p><p>Azure Cognitive services: Speech-to-text conversion of voice of Named Users only.</p><p> </p><p>O365 (including Teams):</p><p>Corporate Email, Storage and Communications</p><p> </p></td><td valign="top"><p>Azure: Data residency choice available:  North America East or North Europe - Ireland.</p><p> </p><p>Landis Policy Call Recording for Teams:</p><p>Call recordings can be stored in Customer’s Azure also.</p></td><td valign="top"><p><a href="https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA">Licensing Documents (microsoft.com)</a></p><p> </p><p><a href="https://privacy.microsoft.com/en-us/privacystatement">Microsoft Privacy Statement – Microsoft privacy</a></p><p> </p><p> </p><p> </p></td></tr><tr><td valign="top"><p>Freshworks Inc.</p><p>2950 S. Delaware Street, Suite 201, San Mateo, CA 94403, US</p><p> </p></td><td valign="top">Freshdesk: Customer service</td><td valign="top">Worldwide</td><td valign="top"><p><a href="https://www.freshworks.com/privacy/">Refreshing Cloud Business Suite | Privacy Notice Freshworks Inc</a></p><p> </p><p><a href="https://www.freshworks.com/data-processing-addendum/">Refreshing Cloud Business Software - Freshworks Data Processing Addendum</a></p></td></tr></tbody></table>

The content below is applicable only for EEA, Swiss and UK Customers. If your organization is based out of other countries, then it does not apply to you.

Whenever we transfer your personal data out to third countries, we ensure a similar degree of protection is afforded to it by employing at least one (or more) of the following safeguards:

* We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see [Data protection adequacy for non-EU countries](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).
* Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see  [ Standard Contractual Clauses (SCC) - European Commission ](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en). In these cases, due diligence of the legal system in the third country to which personal data will be transferred is carried out; the rules for disclosure to and access by government agencies is verified as is whether the service provider is bound by these laws. The likelihood that the service provider will be disclosing personal data of Landis to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for: to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for: to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for:
* notifying Landis to the extent permitted by law, if a government demand extends to the exporter’s data;
* providing an opportunity to resist production; and
* complying with its obligation to notify Landis that it can no longer comply with the requirements of the model contract clauses and cease processing the personal data in the event of any government demand that would not allow it in practice to comply with the contractual clauses.

Landis will confirm, on the basis of the due diligence carried out, that the model contract clauses, in conjunction with any other applicable contractual terms for the relationship, are sufficient to address any issues raised as to the protection of personal data in the third country in that context or whether the circumstances require more specific terms.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

### Security, compliance and certification assurance.

At Landis, we have a security and compliance team actively working to keep your information protected, auditing the security posture and improving safeguards from unauthorized access, accidental loss, disclosure or destruction. Toward this, we employ physical, technical, administrative, and organisational safeguards to protect the personal information we collect and process. Administrative and organisational policies and procedures are documented in the Landis Information Security Management System (ISMS) where appropriate controls are designed to maintain an adequate level of data confidentiality, integrity and availability.

Landis has ISO/IEC 27001:2022 certification. Independent technical vulnerability scanning and penetration testing are performed periodically as required by ISO/IEC 27001:2022.

### Your data protection rights.

You have the right to:

* Be informed about the collection and use of your personal data. This includes being provided with clear, transparent, and easily understandable information about how and why we use your data, who we share it with, and how long we retain it.
* Receive information about how and why your data is used when we collect or use your personal data.
* Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
* Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
* Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), if it is shown we have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
* Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
* Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c ) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
* Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
* Receive notice of automated decision making and profiling undertaken by us and have an opportunity to object to such solely automated decisions when it has legal or similarly significant effect on you.
* Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the above rights, please contact us at <compliance@landistechnologies.com>.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

In exercising these rights, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within the timeframes set by applicable law and regulations.

In relation to Landis Services, we are Processor (and not Controller under GDPR) and hence all the data subject rights related to Landis Services should be directed to the Controller.&#x20;

&#x20;

### Special information for Residents of California, USA

In relation to Landis Services, we are Service Provider (and not Business under CCPA) and hence all the data subject rights related to Landis Services should be directed to the Business who would then engage us.

If you wish to exercise any of the data protection rights, please contact us at <compliance@landistechnologies.com> or write to us via postal mail to the below mentioned address:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522, United States

&#x20;                                                                                              &#x20;

### Data retention.

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including contact, identity, financial and transaction data) for seven years after ceasing to be a customer for taxation purposes.

In cases where we decide the means and purpose of processing and act as controller, you can ask us to delete your data and we shall address it in a timely manner, subject to legal and regulatory obligations and keep you informed of it. In other cases where we act as service provider or processor, we will route your requests to the Business or Controller for actioning your request to delete your data. We may anonymise your personal data so that it can no longer be associated with you for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

### Our Commitment to Data Protection.

Landis is committed to the highest standards of information security, privacy and transparency. Towards this, Landis complies with data protection laws around the world where we process information and protect data subject rights. These include:&#x20;

·         EU Regulation 2016/679 (the GDPR)

·         EU Regulation 2018/1725

·         UK General Data Protection Regulation (UK GDPR)

·         UK Data Protection Act 2018 (DPA 2018)

·         California Consumer Privacy Act of 2018 (CCPA)

·         Swiss Federal Act on Data Protection (FADP)

### Future changes to this Privacy notice.

As our services evolve, this Privacy notice may change or other privacy policies may be written and posted specific to new offerings or to keep pace with data privacy laws. When changes are substantial, we will endeavour to make you aware of any forthcoming changes by attempting to contact you via our user interfaces, portals, or through your partner or reseller. If you have questions or comments on a future privacy notice, you may write us at <compliance@landistechnologies.com>.

### Questions for Landis.

If you have any questions about how we collect, store and use personal information, or if you have any other privacy-related questions, please contact us by email at <compliance@landistechnologies.com>.

***

#### Prior Versions

[August 2025](/legal/privacy/2025-08)

[May 2025](/legal/privacy/2025-05)

[February 2024](/legal/privacy/2024-02)

&#x20;


# 2025-08

#### Click [here](/legal/privacy) for the current privacy policy.

***

## Landis Technologies Privacy Notice

### Legal information

At Landis Technologies LLC (“Landis” or “we” or “us”), we care about privacy, security and transparency; these are core tenets in our company’s mission. Toward that, this privacy notice tells you what to expect when Landis collects personal information about you, including:

•       How Landis collects data;

•       Understanding who controls your data;

•       Landis’s lawful basis for processing your data;

•       Understanding Landis services;

•       Information sharing and transborder flows;

•       Security, compliance and certification assurance;

•       Your data protection rights;

•       Special information for Residents of California, USA

•       Data retention;

•       Our Commitment to Data Protection and

•       Future changes to this Privacy notice.

Landis Technologies LLC has a registered address at 1120 Division Hwy, Ephrata, PA 17522, United States. The main website for Landis is <https://landistechnologies.com/>

This privacy notice is effective as of August 2025.

&#x20;

### How Landis collects data.

One of the purposes of this Privacy notice is to explain how we collect and process personal data. The primary ways we collect information are as follows: (a) by visiting one of our websites; (b) by subscribing to our service purchased by your Employer or Business from Landis

Please be informed that this website is not intended for children, defined as age 15 and under; we absolutely do not knowingly collect data from children and will immediately delete it if discovered.

We encourage you to read this Privacy notice. It has been written to ensure you understand how we collect information, how it is safeguarded, what is collected, how it is processed, where it is processed, with whom we may share it, and your rights under the law.

&#x20;

### Understanding who controls your data.

When you subscribe to Landis services as a Named User, we act as a Data Processor (“Processor”) under the instructions of the Data Controller. In this instance, all future requests or exercises of your rights must be made to the Controller.

When the Landis service is used in the context of US healthcare, a Business Associate Agreement between Landis and the Customer/Partner is required. We use appropriate safeguards to prevent the use or disclosure of ePHI other than as provided for in the agreement. We use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that is created, received, maintained, or transmitted via the service on behalf of the subscribed Covered Entity or Business Associate.

When you share information with us directly by visiting our website, Landis acts as a Data Controller (“Controller”) according to the definitions in Article 4 of the GDPR. This Privacy notice applies when we are acting as the Controller with respect to the personal data we process about you. In other words, where we determine the purpose and the means of the processing, we are identified as the Controller and we are responsible for controlling and safeguarding your personal data.

Toward that, we have assigned a Privacy Officer to superintend all aspects of this Privacy notice, ensuring your questions are answered and your rights are respected. Whenever you have questions, you should contact the Privacy Officer via one of the venues below:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

Email:<compliance@landistechnologies.com>

### Landis’s lawful basis for processing your data.

Landis will only process your data according to the allowance permitted by law. In most instances, we will only use your data in the following situations:

* when you provide us with your consent to process your personal data which may be revoked by you at any time and for any reason;
* when it may be necessary for our legitimate interest;
* when we may need to respond to a legal requirement or regulatory action; and
* where we need to fulfill our obligation to provide services when you subscribe to our services.

In the following table, we describe ways your personal information may be used; each of these uses are tied to a legal basis for processing. Further, we have also outlined wherever we have a legitimate interest to process your data where appropriate.

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Processing Activity</td><td valign="top">Personal Data</td><td valign="top">Lawful Basis</td></tr><tr><td valign="top">Requesting information and relationship management including emails to us, requests for marketing information, enquiries about services, responding to feedback, notifying you about changes to our terms and conditions, notifying you about changes to our Privacy notice, sending you communication through our newsletters and news bulletins, asking you to update your contact information, communicating with you about our service.</td><td valign="top">Identity data, contact data, communication data, marketing preferences.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. (c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations). (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.</td></tr><tr><td valign="top">Subscribing to Landis services.</td><td valign="top">Name, email address, regional settings, call detail records, call participants to scheduled conferences, media streams and recordings, connection history, technical information about your device hardware and operating system, call diagnostics, last login and operating system, last active and connected date (O365), user ID, time zone, administrative flags, localisation.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Service desk support for the Landis service.</td><td valign="top">If working with our service desk to troubleshoot an issue, we may also gather information about the type of computer systems you use, including associated devices such as microphones and video cameras as these are relevant to the services offered by Landis. The information may also include your IP address, operating system, browser type, language preferences, and other relevant details to help Landis ensure your service is working correctly.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Website analytics.</td><td valign="top">Please be informed that we use a third-party analytics service called Google Analytics to collect, analyze and tally metrics regarding website visits. Analytics help us to determine many things, including the quantity of visitors over time, the geographic location from which visitors arrive, timeframes of high and low usage, the sites most frequented, the pages most frequented, and other helpful data. The Company processes data in ways to ensure individual identity is not stored, only anonymous metrics. Furthermore, it is forbidden for Google to determine, or attempt to determine, the identity of individuals visiting our websites, and this anonymity is inherited by Landis.</td><td valign="top">Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</td></tr><tr><td valign="top">Recruitment process and employment in Landis.</td><td valign="top">Personal data including demographics, contact information, grades, certifications, CVs, general data, tests and other government issued identity documents.</td><td valign="top"><p>Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</p><p>(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests</p></td></tr></tbody></table>

&#x20;

Automated decision making and profiling

Landis reserves the right to use AI (Artificial Intelligence) and non-AI based computational logic to automate its operations and shall provide just in time privacy notices where relevant. When such solely automated decisions significantly impact the rights of individuals concerned, we shall provide notice and opportunity to object to such processing.

Profiling is undertaken using website analytics in pursuance of our legitimate interests and as outlined in the above table in this section ‘Landis’s lawful basis for processing your data’.

### Understanding Landis services.

This section applies to users of Landis services. If you only use the Landis public website, this section does not apply to you.

Landis services are driven by an Internet-based communication platform designed to enable business users to communicate using voice calls. The person adding you for the first time to an organisation will provide certain information about you for provisioning, such as your name, company name and work email address.

Wherever possible, the media associated with all Landis originating or terminating audio communications (“calls”) is encrypted. Calls are recorded and saved using Landis’s recording services. Recordings saved using Landis’s recording services products cannot, under any circumstances, be accessed by Landis employees without your organization’s written permission. Where you have given us your consent, we may monitor call metrics to investigate bugs and service issues. Call records will not be made available to anyone outside of Landis without the prior consent of the organisation whose Landis services account was used to originate the calls. Landis reserves the right to anonymize and save your data for any research or statistical purposes.

&#x20;

The Type of Personal Data we collect to provide our MS Teams related services include

·         Named Users Data: Full Name, Email Address, IP Address, User Role

·         Communications Data: The Call Participant Data which includes Name and Email address of the Named Users and the individuals who either receive or make calls to them. The Call Logs Data which include Microsoft Unique Identifier and call metrics. The Audit Logs generated by the Services which capture the user activities, IP address for support and tracking purposes.

·         Landis Policy Call Recording for Teams: Audio streams covering both ends of the call and Speech-to-text conversion of Named Users alone (for training and quality assurance purpose)

·         Landis Attendant Console AI Prompts: AI prompts created based on the call transcripts to aid follow up activities.

&#x20;

### Information sharing and transborder flows.

Landis respects your right to privacy and we do not use or share your personal information in any other way beyond what has been written in this Privacy notice. For instance, we do not sell your information to anyone, including but not limited to third parties for their own marketing use.

As a Data Processor, Landis is acting under the instructions of the Data Controller and may share your data with the Controller in support of your service.

We will inform you or your Data Controller if we are required to share your information under any of the following circumstances: (i) to the extent that we are required to do so by applicable law, by a governmental body or by a law enforcement agency, or for crime prevention purposes; (ii) in connection with any legal proceedings (including prospective legal proceedings); (iii) in order to establish or defend our legal rights; (iv) in the event that we buy or sell any business or assets, in which case we may disclose your personal data to the prospective sellers or buyer of such business or assets; or (v) if a third party acquires all (or substantially all) of our business and/or assets, we may disclose your personal information to that third party in connection with the acquisition.

A list of the service subprocessors of Landis Services are provided below:

·         Microsoft Corporation

·         Freshworks Inc.

The content below is applicable only for EEA, Swiss and UK Customers. If your organization is based out of other countries, then it does not apply to you.

Whenever we transfer your personal data out to third countries, we ensure a similar degree of protection is afforded to it by employing at least one (or more) of the following safeguards:

* We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see [Data protection adequacy for non-EU countries](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).
* Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see [ Standard Contractual Clauses (SCC) - European Commission ](https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en). In these cases, due diligence of the legal system in the third country to which personal data will be transferred is carried out; the rules for disclosure to and access by government agencies is verified as is whether the service provider is bound by these laws. The likelihood that the service provider will be disclosing personal data of Landis to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for:
* notifying Landis to the extent permitted by law, if a government demand extends to the exporter’s data;
* providing an opportunity to resist production; and
* complying with its obligation to notify Landis that it can no longer comply with the requirements of the model contract clauses and cease processing the personal data in the event of any government demand that would not allow it in practice to comply with the contractual clauses.

Landis will confirm, on the basis of the due diligence carried out, that the model contract clauses, in conjunction with any other applicable contractual terms for the relationship, are sufficient to address any issues raised as to the protection of personal data in the third country in that context or whether the circumstances require more specific terms.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

### Security, compliance and certification assurance.

At Landis, we have a security and compliance team actively working to keep your information protected, auditing the security posture and improving safeguards from unauthorized access, accidental loss, disclosure or destruction. Toward this, we employ physical, technical, administrative, and organisational safeguards to protect the personal information we collect and process. Administrative and organisational policies and procedures are documented in the Landis Information Security Management System (ISMS) where appropriate controls are designed to maintain an adequate level of data confidentiality, integrity and availability.

Landis has ISO/IEC 27001:2022 certification. Independent technical vulnerability scanning and penetration testing are performed periodically as required by ISO/IEC 27001:2022.

### Your data protection rights.

You have the right to:

* You have the right to be informed about the collection and use of your personal data. This includes being provided with clear, transparent, and easily understandable information about how and why we use your data, who we share it with, and how long we retain it.
* Receive information about how and why your data is used when we collect or use your personal data.
* Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
* Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
* Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), if it is shown we have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
* Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
* Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c ) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
* Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
* Receive notice of automated decision making and profiling undertaken by us and have an opportunity to object to such solely automated decisions when it has legal or similarly significant effect on you.
* Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the above rights, please contact us at <compliance@landistechnologies.com>.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

In exercising these rights, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within the timeframes set by applicable law and regulations.

In relation to Landis Services, we are Processor (and not Controller under GDPR) and hence all the data subject rights related to Landis Services should be directed to the Controller.&#x20;

&#x20;

### Special information for Residents of California, USA

In relation to Landis Services, we are Service Provider (and not Business under CCPA) and hence all the data subject rights related to Landis Services should be directed to the Business who would then engage us.

If you wish to exercise any of the data protection rights, please contact us at <compliance@landistechnologies.com> or write to us via postal mail to the below mentioned address:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

&#x20;                                                                                              &#x20;

### Data retention.

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including contact, identity, financial and transaction data) for seven years after ceasing to be a customer for taxation purposes.

In cases where we decide the means and purpose of processing and act as controller, you can ask us to delete your data and we shall address it in a timely manner, subject to legal and regulatory obligations and keep you informed of it. In other cases where we act as service provider or processor, we will route your requests to the Business or Controller for actioning your request to delete your data. We may anonymise your personal data so that it can no longer be associated with you for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

### Our Commitment to Data Protection.

Landis is committed to the highest standards of information security, privacy and transparency. Towards this, Landis complies with data protection laws around the world where we process information and protect data subject rights. These include:&#x20;

·         EU Regulation 2016/679 (the GDPR)

·         EU Regulation 2018/1725

·         UK General Data Protection Regulation (UK GDPR)

·         UK Data Protection Act 2018 (DPA 2018)

·         California Consumer Privacy Act of 2018 (CCPA)

·         Swiss Federal Act on Data Protection (FADP)

### Future changes to this Privacy notice.

As our services evolve, this Privacy notice may change or other privacy policies may be written and posted specific to new offerings or to keep pace with data privacy laws. When changes are substantial, we will endeavour to make you aware of any forthcoming changes by attempting to contact you via our user interfaces, portals, or through your partner or reseller. If you have questions or comments on a future privacy notice, you may write us at <compliance@landistechnologies.com>.

### Questions for Landis.

If you have any questions about how we collect, store and use personal information, or if you have any other privacy-related questions, please contact us by email at <compliance@landistechnologies.com>.


# 2025-05

#### Click [here](/legal/privacy) for the current privacy policy.

***

## Landis Technologies Privacy Notice

### Legal information

At Landis Technologies LLC (“Landis” or “we” or “us”), we care about privacy, security and transparency; these are core tenets in our company’s mission. Toward that, this privacy notice tells you what to expect when Landis collects personal information about you, including:

•       How Landis collects data;

•       Understanding who controls your data;

•       Landis’s lawful basis for processing your data;

•       Understanding Landis services;

•       Information sharing and transborder flows;

•       Security, compliance and certification assurance;

•       Your data protection rights;

•       Special information for Residents of California, USA

•       Data retention;

•       Our Commitment to Data Protection and

•       Future changes to this Privacy notice.

Landis Technologies LLC has a registered address at 1120 Division Hwy, Ephrata, PA 17522, United States. The main website for Landis is <https://landistechnologies.com/>

&#x20;

This privacy notice is effective as of May 2025.

&#x20;

### How Landis collects data.

One of the purposes of this Privacy notice is to explain how we collect and process personal data. The primary ways we collect information are as follows: (a) by visiting one of our websites; (b) by subscribing to our service purchased by your Employer or Business from Landis

Please be informed that this website is not intended for children, defined as age 15 and under; we absolutely do not knowingly collect data from children and will immediately delete it if discovered.

We encourage you to read this Privacy notice. It has been written to ensure you understand how we collect information, how it is safeguarded, what is collected, how it is processed, where it is processed, with whom we may share it, and your rights under the law.

&#x20;

### Understanding who controls your data.

When you subscribe to Landis services as a Named User, we act as a Data Processor (“Processor”) under the instructions of the Data Controller. In this instance, all future requests or exercises of your rights must be made to the Controller.

When the Landis service is used in the context of US healthcare, a Business Associate Agreement between Landis and the Customer/Partner is required. We use appropriate safeguards to prevent the use or disclosure of ePHI other than as provided for in the agreement. We use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that is created, received, maintained, or transmitted via the service on behalf of the subscribed Covered Entity or Business Associate.

When you share information with us directly by visiting our website, Landis acts as a Data Controller (“Controller”) according to the definitions in Article 4 of the GDPR. This Privacy notice applies when we are acting as the Controller with respect to the personal data we process about you. In other words, where we determine the purpose and the means of the processing, we are identified as the Controller and we are responsible for controlling and safeguarding your personal data.

Toward that, we have assigned a Privacy Officer to superintend all aspects of this Privacy notice, ensuring your questions are answered and your rights are respected. Whenever you have questions, you should contact the Privacy Officer via one of the venues below:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

Email:<compliance@landistechnologies.com>

### Landis’s lawful basis for processing your data.

Landis will only process your data according to the allowance permitted by law. In most instances, we will only use your data in the following situations:

* when you provide us with your consent to process your personal data which may be revoked by you at any time and for any reason;
* when it may be necessary for our legitimate interest;
* when we may need to respond to a legal requirement or regulatory action; and
* where we need to fulfill our obligation to provide services when you subscribe to our services.

In the following table, we describe ways your personal information may be used; each of these uses are tied to a legal basis for processing. Further, we have also outlined wherever we have a legitimate interest to process your data where appropriate.

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Processing Activity</td><td valign="top">Personal Data</td><td valign="top">Lawful Basis</td></tr><tr><td valign="top">Requesting information and relationship management including emails to us, requests for marketing information, enquiries about services, responding to feedback, notifying you about changes to our terms and conditions, notifying you about changes to our Privacy notice, sending you communication through our newsletters and news bulletins, asking you to update your contact information, communicating with you about our service.</td><td valign="top">Identity data, contact data, communication data, marketing preferences.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. (c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations). (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.</td></tr><tr><td valign="top">Subscribing to Landis services.</td><td valign="top">Name, email address, regional settings, call detail records, call participants to scheduled conferences, media streams and recordings, connection history, technical information about your device hardware and operating system, call diagnostics, last login and operating system, last active and connected date (O365), user ID, time zone, administrative flags, localisation.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Service desk support for the Landis service.</td><td valign="top">If working with our service desk to troubleshoot an issue, we may also gather information about the type of computer systems you use, including associated devices such as microphones and video cameras as these are relevant to the services offered by Landis. The information may also include your IP address, operating system, browser type, language preferences, and other relevant details to help Landis ensure your service is working correctly.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Website analytics.</td><td valign="top">Please be informed that we use a third-party analytics service called Google Analytics to collect, analyze and tally metrics regarding website visits. Analytics help us to determine many things, including the quantity of visitors over time, the geographic location from which visitors arrive, timeframes of high and low usage, the sites most frequented, the pages most frequented, and other helpful data. The Company processes data in ways to ensure individual identity is not stored, only anonymous metrics. Furthermore, it is forbidden for Google to determine, or attempt to determine, the identity of individuals visiting our websites, and this anonymity is inherited by Landis.</td><td valign="top">Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</td></tr><tr><td valign="top">Recruitment process and employment in Landis.</td><td valign="top">Personal data including demographics, contact information, grades, certifications, CVs, general data, tests and other government issued identity documents.</td><td valign="top"><p>Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</p><p>(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests</p></td></tr></tbody></table>

&#x20;

Automated decision making and profiling

Landis reserves the right to use AI (Artificial Intelligence) and non-AI based computational logic to automate its operations and shall provide just in time privacy notices where relevant. When such solely automated decisions significantly impact the rights of individuals concerned, we shall provide notice and opportunity to object to such processing.

Profiling is undertaken using website analytics in pursuance of our legitimate interests and as outlined in the above table in this section ‘Landis’s lawful basis for processing your data’.

### Understanding Landis services.

This section applies to users of Landis services. If you only use the Landis public website, this section does not apply to you.

Landis services are driven by an Internet-based communication platform designed to enable business users to communicate using voice calls. The person adding you for the first time to an organisation will provide certain information about you for provisioning, such as your name, company name and work email address.

Wherever possible, the media associated with all Landis originating or terminating audio communications (“calls”) is encrypted. Calls are recorded and saved using Landis’s recording services. Recordings saved using Landis’s recording services products cannot, under any circumstances, be accessed by Landis employees without your organization’s written permission.  Where you have given us your consent, we may monitor call metrics to investigate bugs and service issues. Call records will not be made available to anyone outside of Landis without the prior consent of the organisation whose Landis services account was used to originate the calls. Landis reserves the right to anonymize and save your data for any research or statistical purposes.

&#x20;

The Type of Personal Data we collect to provide our MS Teams related services include

·         Named Users Data: Full Name, Email Address, IP Address, User Role

·         Communications Data: The Call Participant Data which includes Name and Email address of the Named Users and the individuals who either receive or make calls to them. The Call Logs Data which include Microsoft Unique Identifier and call metrics. The Audit Logs generated by the Services which capture the user activities, IP address for support and tracking purposes.

·         Landis Policy Call Recording for Teams: Audio streams covering both ends of the call and Speech-to-text conversion of Named Users alone (for training and quality assurance purpose)

·         Landis Attendant Console AI Prompts: AI prompts created based on the call transcripts to aid follow up activities.

&#x20;

### Information sharing and transborder flows.

Landis respects your right to privacy and we do not use or share your personal information in any other way beyond what has been written in this Privacy notice. For instance, we do not sell your information to anyone, including but not limited to third parties for their own marketing use.

As a Data Processor, Landis is acting under the instructions of the Data Controller and may share your data with the Controller in support of your service.

We will inform you or your Data Controller if we are required to share your information under any of the following circumstances: (i) to the extent that we are required to do so by applicable law, by a governmental body or by a law enforcement agency, or for crime prevention purposes; (ii) in connection with any legal proceedings (including prospective legal proceedings); (iii) in order to establish or defend our legal rights; (iv) in the event that we buy or sell any business or assets, in which case we may disclose your personal data to the prospective sellers or buyer of such business or assets; or (v) if a third party acquires all (or substantially all) of our business and/or assets, we may disclose your personal information to that third party in connection with the acquisition.

A list of the service subprocessors of Landis Services are provided below:

·         Microsoft Corporation

·         Freshworks Inc.

The content below is applicable only for EEA, Swiss and UK Customers. If your organization is based out of other countries, then it does not apply to you.

Whenever we transfer your personal data out to third countries, we ensure a similar degree of protection is afforded to it by employing at least one (or more) of the following safeguards:

* We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see [Data protection adequacy for non-EU countries](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en).
* Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see [ Standard Contractual Clauses (SCC) - European Commission ](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en). In these cases, due diligence of the legal system in the third country to which personal data will be transferred is carried out; the rules for disclosure to and access by government agencies is verified as is whether the service provider is bound by these laws. The likelihood that the service provider will be disclosing personal data of Landis to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for:
* * notifying Landis to the extent permitted by law, if a government demand extends to the exporter’s data;
* * providing an opportunity to resist production; and
* * complying with its obligation to notify Landis that it can no longer comply with the requirements of the model contract clauses and cease processing the personal data in the event of any government demand that would not allow it in practice to comply with the contractual clauses.

Landis will confirm, on the basis of the due diligence carried out, that the model contract clauses, in conjunction with any other applicable contractual terms for the relationship, are sufficient to address any issues raised as to the protection of personal data in the third country in that context or whether the circumstances require more specific terms.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

### Security, compliance and certification assurance.

At Landis, we have a security and compliance team actively working to keep your information protected, auditing the security posture and improving safeguards from unauthorized access, accidental loss, disclosure or destruction. Toward this, we employ physical, technical, administrative, and organisational safeguards to protect the personal information we collect and process. Administrative and organisational policies and procedures are documented in the Landis Information Security Management System (ISMS) where appropriate controls are designed to maintain an adequate level of data confidentiality, integrity and availability.

Landis has ISO/IEC 27001:2022 certification. Independent technical vulnerability scanning and penetration testing are performed periodically as required by ISO/IEC 27001:2022.

### Your data protection rights.

You have the right to:

* Receive information when we collect and use your personal data.
* Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
* Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
* Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), if it is shown we have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
* Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
* Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c ) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
* Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
* Receive notice of automated decision making and profiling undertaken by us and have an opportunity to object to such solely automated decisions when it has legal or similarly significant effect on you.
* Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the above rights, please contact us at <compliance@landistechnologies.com>.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

In exercising these rights, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within the timeframes set by applicable law and regulations.

&#x20;

In relation to Landis Services, we are Processor (and not Controller under GDPR) and hence all the data subject rights related to Landis Services should be directed to the Controller.&#x20;

&#x20;

### Special information for Residents of California, USA

In relation to Landis Services, we are Service Provider (and not Business under CCPA) and hence all the data subject rights related to Landis Services should be directed to the Business who would then engage us.

If you wish to exercise any of the data protection rights, please contact us at <compliance@landistechnologies.com> or write to us via postal mail to the below mentioned address:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

&#x20;                                                                                              &#x20;

### Data retention.

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including contact, identity, financial and transaction data) for seven years after ceasing to be a customer for taxation purposes.

In cases where we decide the means and purpose of processing and act as controller, you can ask us to delete your data and we shall address it in a timely manner, subject to legal and regulatory obligations and keep you informed of it. In other cases where we act as service provider or processor, we will route your requests to the Business or Controller for actioning your request to delete your data. We may anonymise your personal data so that it can no longer be associated with you for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

### Our Commitment to Data Protection.

Landis is committed to the highest standards of information security, privacy and transparency. Towards this, Landis complies with data protection laws around the world where we process information and protect data subject rights. These include:&#x20;

·         EU Regulation 2016/679 (the GDPR)

·         EU Regulation 2018/1725

·         UK General Data Protection Regulation (UK GDPR)

·         UK Data Protection Act 2018 (DPA 2018)

·         California Consumer Privacy Act of 2018 (CCPA)

·         Swiss Federal Act on Data Protection (FADP)

### Future changes to this Privacy notice.

As our services evolve, this Privacy notice may change or other privacy policies may be written and posted specific to new offerings or to keep pace with data privacy laws. When changes are substantial, we will endeavour to make you aware of any forthcoming changes by attempting to contact you via our user interfaces, portals, or through your partner or reseller. If you have questions or comments on a future privacy notice, you may write us at <compliance@landistechnologies.com>.

### Questions for Landis.

If you have any questions about how we collect, store and use personal information, or if you have any other privacy-related questions, please contact us by email at <compliance@landistechnologies.com>.


# 2024-02

#### Click [here](/legal/privacy) for the current privacy policy.

***

## Landis Technologies Privacy Policy

### Legal information

At Landis Technologies LLC (“Landis” or “we” or “us”), we care about privacy, security and transparency; these are core tenets in our company’s mission. Toward that, this privacy notice tells you what to expect when Landis collects personal information about you, including:

•       How Landis collects data;

•       Understanding who controls your data;

•       Landis’s lawful basis for processing your data;

•       Understanding Landis services;

•       Information sharing and transborder flows;

•       Security, compliance and certification assurance;

•       Your data protection rights;

•       Special information for Residents of California, USA

•       Data retention;

•       Our Commitment to Data Protection and

•       Future changes to this Privacy notice.

Landis Technologies LLC has a registered address at 1120 Division Hwy, Ephrata, PA 17522, United States. The main website for Landis is <https://landistechnologies.com/>

&#x20;

This privacy notice is effective as of February 2024.

### How Landis collects data.

One of the purposes of this Privacy notice is to explain how we collect and process personal data. The primary ways we collect information are as follows: (a) by visiting one of our websites; (b) by subscribing to our service purchased by your Employer or Business from Landis

Please be informed that this website is not intended for children, defined as age 15 and under; we absolutely do not knowingly collect data from children and will immediately delete it if discovered.

We encourage you to read this Privacy notice. It has been written to ensure you understand how we collect information, how it is safeguarded, what is collected, how it is processed, where it is processed, with whom we may share it, and your rights under the law.

### Understanding who controls your data.

When you subscribe to Landis services as a Named User, we act as a Data Processor (“Processor”) under the instructions of the Data Controller. In this instance, all future requests or exercises of your rights must be made to the Controller.

When the Landis service is used in the context of US healthcare, a Business Associate Agreement between Landis and the Customer/Partner is required. We use appropriate safeguards to prevent the use or disclosure of ePHI other than as provided for in the agreement. We use administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that is created, received, maintained, or transmitted via the service on behalf of the subscribed Covered Entity or Business Associate.

When you share information with us directly by visiting our website, Landis acts as a Data Controller (“Controller”) according to the definitions in Article 4 of the GDPR. This Privacy notice applies when we are acting as the Controller with respect to the personal data we process about you. In other words, where we determine the purpose and the means of the processing, we are identified as the Controller and we are responsible for controlling and safeguarding your personal data.

Toward that, we have assigned a Privacy Officer to superintend all aspects of this Privacy notice, ensuring your questions are answered and your rights are respected. Whenever you have questions, you should contact the Privacy Officer via one of the venues below:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

Email: <support@landistechnologies.com>

### Landis’s lawful basis for processing your data.

Landis will only process your data according to the allowance permitted by law. In most instances, we will only use your data in the following situations:

* when you provide us with your consent to process your personal data which may be revoked by you at any time and for any reason;
* when it may be necessary for our legitimate interest;
* when we may need to respond to a legal requirement or regulatory action; and
* where we need to fulfill our obligation to provide services when you subscribe to our services.

In the following table, we describe ways your personal information may be used; each of these uses are tied to a legal basis for processing. Further, we have also outlined wherever we have a legitimate interest to process your data where appropriate.

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top">Processing Data</td><td valign="top">Personal Data</td><td valign="top">Lawful Basis</td></tr><tr><td valign="top">Requesting information and relationship management including emails to us, requests for marketing information, enquiries about services, responding to feedback, notifying you about changes to our terms and conditions, notifying you about changes to our Privacy notice, sending you communication through our newsletters and news bulletins, asking you to update your contact information, communicating with you about our service.</td><td valign="top">Identity data, contact data, communication data, marketing preferences.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract. (c) Legal obligation: the processing is necessary for you to comply with the law (not including contractual obligations). (f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.</td></tr><tr><td valign="top">Subscribing to Landis services.</td><td valign="top">Name, email address, regional settings, call detail records, call participants to scheduled conferences, media streams and recordings, connection history, technical information about your device hardware and operating system, call diagnostics, last login and operating system, last active and connected date (O365), userID, time zone, administrative flags, localisation.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Service desk support for the Landis service.</td><td valign="top">If working with our service desk to troubleshoot an issue, we may also gather information about the type of computer systems you use, including associated devices such as microphones and video cameras as these are relevant to the services offered by Landis. The information may also include your IP address, operating system, browser type, language preferences, and other relevant details to help Landis ensure your service is working correctly.</td><td valign="top">Article 6: (b) Contract: the processing is necessary for a contract you have with the individual, or because they have asked you to take specific steps before entering into a contract.</td></tr><tr><td valign="top">Website analytics.</td><td valign="top">Please be informed that we use a third-party analytics service called Google Analytics to collect, analyze and tally metrics regarding website visits. Analytics help us to determine many things, including the quantity of visitors over time, the geographic location from which visitors arrive, timeframes of high and low usage, the sites most frequented, the pages most frequented, and other helpful data. The Company processes data in ways to ensure individual identity is not stored, only anonymous metrics. Furthermore, it is forbidden for Google to determine, or attempt to determine, the identity of individuals visiting our websites, and this anonymity is inherited by Landis.</td><td valign="top">Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</td></tr><tr><td valign="top">Recruitment process and employment in Landis.</td><td valign="top">Personal data including demographics, contact information, grades, certifications, CVs, general data, tests and other government issued identity documents.</td><td valign="top"><p>Article 6: (a) Consent: the individual has given clear consent to process personal data for a specific purpose.</p><p>(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests</p></td></tr></tbody></table>

### Understanding Landis services.

This section applies to users of Landis services. If you only use the Landis public website, this section does not apply to you.

Landis services are driven by an Internet-based communication platform designed to enable business users to communicate using voice calls. The person adding you for the first time to an organisation will provide certain information about you for provisioning, such as your name, company name and work email address.

Wherever possible, the media associated with all Landis originating or terminating audio communications (“calls”) is encrypted. Calls are recorded and saved using Landis’s recording services. Recordings saved using Landis’s recording services products cannot, under any circumstances, be accessed by Landis employees without your organization’s written permission. Speech-to-text conversion of Named Users alone is done by Landis for the purpose of training and quality assurance. Where you have given us your consent, we may monitor call metrics to investigate bugs and service issues. Call records will not be made available to anyone outside of Landis without the prior consent of the organisation whose Landis services account was used to originate the calls. Landis reserves the right to anonymize and save your data for any research or statistical purposes.

&#x20;

The Type of Personal Data we collect to provide our MS Teams related services include

·         Named Users Data: Full Name, Email Address, IP Address, User Role

·         Communications Data: The Call Participant Data which includes Name and Email address of the Named Users and the individuals who either receive or make calls to them. The Call Logs Data which include Microsoft Unique Identifier and call metrics. The Audit Logs generated by the Services which capture the user activities, IP address for support and tracking purposes.

·         Landis Policy Call Recording for Teams: Audio streams covering both ends of the call and Speech-to-text conversion of Named Users alone (for training and quality assurance purpose)

&#x20;

### Information sharing and transborder flows.

Landis respects your right to privacy and we do not use or share your personal information in any other way beyond what has been written in this Privacy notice. For instance, we do not sell your information to anyone, including but not limited to third parties for their own marketing use.

As a Data Processor, Landis is acting under the instructions of the Data Controller and may share your data with the Controller in support of your service.

We will inform you or your Data Controller if we are required to share your information under any of the following circumstances: (i) to the extent that we are required to do so by applicable law, by a governmental body or by a law enforcement agency, or for crime prevention purposes; (ii) in connection with any legal proceedings (including prospective legal proceedings); (iii) in order to establish or defend our legal rights; (iv) in the event that we buy or sell any business or assets, in which case we may disclose your personal data to the prospective sellers or buyer of such business or assets; or (v) if a third party acquires all (or substantially all) of our business and/or assets, we may disclose your personal information to that third party in connection with the acquisition.

A list of the external third parties are provided below:

·         Microsoft Corporation

·         Freshworks Inc.

·         Intuit Mailchimp

The content below is applicable only for EEA, Swiss and UK Customers. If your organization is based out of other countries, then it does not apply to you.

Whenever we transfer your personal data out to third countries, we ensure a similar degree of protection is afforded to it by employing at least one (or more) of the following safeguards:

* We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see [European Commission: Adequacy of the protection of personal data in non-EU countries ](https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en).
* Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe. For further details, see [European Commission: Model contracts for the transfer of personal data to third countries ](https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en). In these cases, due diligence of the legal system in the third country to which personal data will be transferred is carried out; the rules for disclosure to and access by government agencies is verified as is whether the service provider is bound by these laws. The likelihood that the service provider will be disclosing personal data of Landis to the authorities in that third country is evaluated, including categories and volume of personal data transferred, purposes of the processing by the service provider, duration of data retention in the third country and any past practices of such disclosures. The service provider’s policies and procedures for:
* * notifying Landis to the extent permitted by law, if a government demand extends to the exporter’s data;
* * providing an opportunity to resist production; and
* * complying with its obligation to notify Landis that it can no longer comply with the requirements of the model contract clauses and cease processing the personal data in the event of any government demand that would not allow it in practice to comply with the contractual clauses.

Landis will confirm, on the basis of the due diligence carried out, that the model contract clauses, in conjunction with any other applicable contractual terms for the relationship, are sufficient to address any issues raised as to the protection of personal data in the third country in that context or whether the circumstances require more specific terms.

Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

### Security, compliance and certification assurance.

At Landis, we have a security and compliance team actively working to keep your information protected, auditing the security posture and improving safeguards from unauthorized access, accidental loss, disclosure or destruction. Toward this, we employ physical, technical, administrative, and organisational safeguards to protect the personal information we collect and process. Administrative and organisational policies and procedures are documented in the Landis Information Security Management System (ISMS) where appropriate controls are designed to maintain an adequate level of data confidentiality, integrity and availability.

Landis is currently implementing ISO/IEC 27001:2022 and has engaged Allendevaux & Company in its endeavour to attain ISO/IEC 27001:2022 certification which is expected by Q2 2024. Also, independent technical vulnerability scanning and penetration testing are performed through Allendevaux & Company.

### Your data protection rights.

You have the right to:

* Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
* Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
* Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), if it is shown we have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
* Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
* Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c ) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
* Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
* Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the above rights, please contact us at <support@landistechnologies.com>.

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

In exercising these rights, we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. We try to respond to all legitimate requests within the timeframes set by applicable law and regulations.

&#x20;

In relation to Landis Services, we are Processor (and not Controller under GDPR) and hence all the data subject rights related to Landis Services should be directed to the Controller.&#x20;

&#x20;

### Special information for Residents of California, USA

In relation to Landis Services, we are Service Provider (and not Business under CCPA) and hence all the data subject rights related to Landis Services should be directed to the Business who would then engage us.

If you wish to exercise any of the data protection rights, please contact us at <support@landistechnologies.com> or write to us via postal mail to the below mentioned address:

Landis Technologies LLC

Privacy Officer

1120 Division Highway,

Ephrata, PA 17522,

United States

&#x20;                                                                                              &#x20;

### Data retention.

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including contact, identity, financial and transaction data) for seven years after ceasing to be a customer for taxation purposes.

In cases where we decide the means and purpose of processing and act as controller, you can ask us to delete your data and we shall address it in a timely manner, subject to legal and regulatory obligations and keep you informed of it. In other cases where we act as service provider or processor, we will route your requests to the Business or Controller for actioning your request to delete your data. We may anonymise your personal data so that it can no longer be associated with you for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

### Our Commitment to Data Protection.

Landis is committed to the highest standards of information security, privacy and transparency. Towards this, Landis complies with data protection laws around the world where we process information and protect data subject rights. These include:&#x20;

·         EU Regulation 2016/679 (the GDPR)

·         EU Regulation 2018/1725

·         UK General Data Protection Regulation (UK GDPR)

·         UK Data Protection Act 2018 (DPA 2018)

·         California Consumer Privacy Act of 2018 (CCPA)

·         Swiss Federal Act on Data Protection (FADP)

### Future changes to this Privacy notice.

As our services evolve, this Privacy notice may change or other privacy policies may be written and posted specific to new offerings or to keep pace with data privacy laws. When changes are substantial, we will endeavour to make you aware of any forthcoming changes by attempting to contact you via our user interfaces, portals, or through your partner or reseller. If you have questions or comments on a future privacy notice, you may write us at <support@landistechnologies.com>.

### Questions for Landis.

If you have any questions about how we collect, store and use personal information, or if you have any other privacy-related questions, please contact us by email at <support@landistechnologies.com>.


# Terms and Conditions

Terms and Conditions

LANDIS CONTACT CENTER FOR MICROSOFT TEAMS & LANDIS ATTENDANT CONSOLE FOR MICROSOFT TEAMS

ACCESS AGREEMENT

THIS ACCESS (“**AGREEMENT**”) GOVERNS AND CONTROLS YOUR ACCESS TO AND USE OF ONE OR MORE SAAS SERVICES (TOGETHER, WHITHER ONE OR MORE, THE “**SERVICE**”) AND CONSTITUTES A BINDING AGREEMENT BETWEEN YOU (“**CUSTOMER**,” “**YOU**,” OR “**YOUR**”) AND LANDIS TECHNOLOGIES, LLC. (“**PROVIDER,**” “**WE**,” OR “**US**”).  BY ACCESSING AND USING THE SERVICE, YOU ARE EXPRESSLY AGREEING TO BE BOUND BY THESE TERMS AND YOU FURTHER REPRESENT AND WARRANT TO US THAT YOU HAVE READ AND UNDERSTAND THESE TERMS AND THAT YOU HAVE THE RIGHT, POWER, AND AUTHORITY TO ENTER INTO THESE TERMS ON YOUR OWN BEHALF OR ON BEHALF OF AN ORGANIZATION.

1\.      Definitions.

a.       "**Aggregated Statistics**" means non-personally identifiable data and information related to Customer's use of the Service that is used by Provider in an aggregate and anonymized manner, including to compile statistical and performance information related to the provision and operation of the Service.

b.      “**Authorized User**” means Customer and Customer’s employees, consultants, contractors, and agents (i) who are authorized by Customer to access and use the Service under the rights granted to Customer pursuant to these Terms; and (ii) for whom access to the Service has been purchased.

c.       "**Customer Data**" means information, data, and other content, if any, in any form or medium, other than Aggregated Statistics, that is submitted, posted, or otherwise transmitted by or on behalf of Customer or an Authorized User through the Service.

d.      "**Documentation**" means Provider's online user manuals, handbooks, guides, and other documentation relating to the Service and available in documentation <https://docs.landis.cloud/>, as may be modified and amended from time to time.

e.       "**Provider IP**" means the Service, the Documentation, and any and all intellectual property provided to Customer or any Authorized User in connection with the foregoing. For the avoidance of doubt, Provider IP includes Aggregated Statistics and any information, data, or other content derived from Customer's access to or use of the Services, but does not include Customer Data.

f.        "**Service**" means one or more of Provider's SaaS services (including the Landis Contact Center for Microsoft Teams or Landis Attendant Console for Microsoft Teams) to which the Customer has subscribed and as more fully described in the relevant Documentation.

g.      “**Service Order**” means the email or other order issued by Provider, or by Provider's partner or reseller, and executed by Customer that sets forth the number of Customer’s Authorized Users, Customer’s monthly fee for the Service, the agreed method of payment, and the Start Date (as hereinafter defined).

h.      “**Start Date”** means the date on which Customer is first granted full access to the Service.

i.        "**Third-Party Products**" means any third-party products that are provided with, incorporated into, or required for access to the Service, including, without limitation, Microsoft Teams, and which are more fully described in the Documentation. &#x20;

j.        **“Trial Period**” means an agreed period, not to exceed 30 days, during which Customer may be entitled to use, without payment, a version of the Service with some limited functionality, for the purpose of determining if Customer wishes to subscribe to the full version of the Service.

2\.      Term.  The term of this Agreement (“**Term**”) shall begin on the **Effective Date** which shall be the earlier to occur of: (i) the beginning of any Trial Period or (ii) the Start Date, and shall continue on a month to month basis until the date Customer’s access to the Service is terminated as provided for in this Agreement (the “**Termination Date**”).

3\.      Access and Use.

a.       Provision of Access. Provider hereby grants Customer a non-exclusive, non-transferable right and license to access and use the Service during the Term, solely for use by Authorized Users in accordance with the terms and conditions of this Agreement. Such use is limited to Customer's internal business use. Provider shall provide to Customer the necessary passwords and network links or connections to allow Customer and Authorized Users to access the Service.

b.      Documentation License. Subject to the terms and conditions contained in this Agreement, Provider hereby grants to Customer a non-exclusive, non-sublicensable, non-transferable license to use the Documentation during the Term solely for Customer's internal business purposes in connection with its use of the Service.

c.       Use Restrictions. Customer shall not use the Service for any purposes beyond the scope of the access granted in this Agreement.  Without limiting the generality of the forgoing, Customer shall not at any time, directly or indirectly, and shall not permit any Authorized Users to: (i) copy, modify, or create derivative works of the Service or Documentation, in whole or in part; (ii) rent, lease, lend, sell, license, sublicense, assign, distribute, publish, transfer, or otherwise make the Service or Documentation to any third party, other than Authorized Users; (iii) reverse engineer, disassemble, decompile, decode, adapt, or otherwise attempt to derive or gain access to any software component of the Service, in whole or in part; (iv) conduct a load test or other type test, or take any other action that may disrupt or otherwise interfere with the Service; (v) remove any proprietary notices from the Service or Documentation; or (vi) use the Service or Documentation in any manner or for any purpose that infringes, misappropriates, or otherwise violates any intellectual property right or other right of any person, or that violates any applicable law.

d.      Reservation of Rights. Provider reserves all rights not expressly granted to Customer in this Agreement. Except for the limited rights and licenses expressly granted under this Agreement, nothing in this Agreement grants, by implication, waiver, estoppel, or otherwise, to Customer or any third party any intellectual property rights or other right, title, or interest in or to the Provider IP.

e.       Suspension. Notwithstanding anything to the contrary in this Agreement, Provider may temporarily suspend Customer's and any Authorized User's access to any portion or all of the Service (in each case a “**Service Suspension**”):

(i)                 if Provider reasonably determines that: (A) there is a threat or attack on the Service or any of the Provider IP; (B) Customer's or any Authorized User's use of the Service disrupts or poses a security risk to the Provider IP or to any other customer or vendor of Provider; (C) Customer, or any Authorized User, is using the Provider IP for fraudulent or illegal activities; (D) subject to applicable law, Customer has ceased to continue its business in the ordinary course, made an assignment for the benefit of creditors or similar disposition of its assets, or become the subject of any bankruptcy, reorganization, liquidation, dissolution, or similar proceeding; or (E) Provider's provision of the Services to Customer or any Authorized User is prohibited by applicable law;

(ii)              if any vendor of Provider has suspended or terminated Provider's access to or use of any third-party services or products required to enable Customer to access the Service; or

(iii)            in accordance with Section 6 (a)(iii) of this Agreement.

Provider shall use commercially reasonable efforts to provide written notice of any Service Suspension to Customer and to provide updates regarding resumption of access to the Services following any Service Suspension. Provider shall use commercially reasonable efforts to resume providing access to the Services as soon as reasonably possible after the event giving rise to the Service Suspension is cured. Provider will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer or any Authorized User may incur as a result of a Service Suspension.&#x20;

f.        Aggregated Statistics. Notwithstanding anything to the contrary in this Agreement, Customer's use of the Service may result in the creation of Aggregated Statistics. As between Provider and Customer, all right, title, and interest in Aggregated Statistics, and all intellectual property rights therein, belong to and are retained solely by Provider. Customer acknowledges that Provider may, depending on Service as outlined in Documentation, compile Aggregated Statistics based on Customer Data input into the Service. Customer agrees that Provider may (i) make Aggregated Statistics publicly available in compliance with applicable law, and (ii) use Aggregated Statistics to the extent and in the manner permitted under applicable law.

4\.      Customer Responsibilities.

a.       General. Customer is responsible and liable for all uses of the Service and Documentation resulting from access provided by Customer, directly or indirectly, whether such access or use is permitted by or in violation of this Agreement. Without limiting the generality of the foregoing, Customer is responsible for all acts and omissions of Authorized Users, and any act or omission by an Authorized User that would constitute a breach of this Agreement if taken by Customer will be deemed a breach of this Agreement by Customer. Customer shall use reasonable efforts to make all Authorized Users aware of this Agreement's provisions as applicable to such Authorized User's use of the Services, and shall cause Authorized Users to comply with such provisions.

b.      Third-Party Products.  Third-Party Products are subject to their own terms and conditions and Customer agrees to abide by such terms and Conditions.

5\.      Service Levels and Support.

a.       Service Levels. Provider shall make commercially reasonable efforts to insure that the Service is available no less than 99.9 percent of the time during any given month.  However, Provider does not guaranty any particular service level or availability of the Service.

b.      Support.  Provider provides telephone and email support as more fully described in the Documentation. Additional support and other professional services may be available from Provider pursuant to a separate agreement and for additional fees. &#x20;

6\.      Fees and Payment.

a.       Fees. Customer shall pay Provider, or Provider's partner or reseller, the monthly fees ("**Fees**") in the amount and by the method set forth in the Service Order.  All payments are to be made as without offset or deduction, with the first payment being due on the Start Date and subsequent payments being due on the same of each month thereafter during the Term. Customer shall make all payments in US dollars on or before the due date set forth in the Service Order. If Customer fails to make any payment when due, without limiting Provider's other rights and remedies: (i) Provider may charge interest on the past due amount at the rate of 1.5% per month, calculated daily and compounded monthly or, if lower, the highest rate permitted under applicable law; (ii) Customer shall reimburse Provider for all reasonable costs incurred by Provider in collecting any late payments or interest, including attorneys' fees, court costs, and collection agency fees; and (iii) if such failure continues for ten (10) days or more, Provider may suspend Customer's and its Authorized Users' access to any portion or all of the Service until such amounts are paid in full.

b.      Taxes. All Fees and other amounts payable by Customer under this Agreement are exclusive of taxes and similar assessments. Customer is responsible for all sales, use, and excise taxes, and any other similar taxes, duties, and charges of any kind imposed by any federal, state, or local governmental or regulatory authority on any amounts payable by Customer hereunder, other than any taxes imposed on Provider's income.

7\.      Confidential Information. From time to time during the Term, either Party may disclose or make available to the other Party information about its business affairs, products, confidential intellectual property, trade secrets, third-party confidential information, and other sensitive or proprietary information, whether orally or in written, electronic, or other form or media/in written or electronic form or media, whether or not marked, designated, or otherwise identified as "confidential" (collectively, "**Confidential Information**"). Confidential Information does not include information that, at the time of disclosure is: (a) in the public domain; (b) known to the receiving Party at the time of disclosure; (c) rightfully obtained by the receiving Party on a non-confidential basis from a third party; or (d) independently developed by the receiving Party. The receiving Party shall not disclose the disclosing Party's Confidential Information to any person or entity, except to the receiving Party's employees who have a need to know the Confidential Information for the receiving Party to exercise its rights or perform its obligations under this Agreement. Notwithstanding the foregoing, each Party may disclose Confidential Information to the limited extent required (i) in order to comply with the order of a court or other governmental body, or as otherwise necessary to comply with applicable law, provided that the Party making the disclosure pursuant to the order shall first have given written notice to the other Party and made a reasonable effort to obtain a protective order; or (ii) to establish a Party's rights under this Agreement, including to make required court filings. On the expiration or termination of the Agreement, the receiving Party shall promptly return to the disclosing Party all copies, whether in written, electronic, or other form or media, of the disclosing Party's Confidential Information, or destroy all such copies and certify in writing to the disclosing Party that such Confidential Information has been destroyed. Each Party's obligations of non-disclosure with regard to Confidential Information are effective as of the Effective Date and will expire five years from the date first disclosed to the receiving Party; provided, however, with respect to any Confidential Information that constitutes a trade secret (as determined under applicable law), such obligations of non-disclosure will survive the termination or expiration of this Agreement for as long as such Confidential Information remains subject to trade secret protection under applicable law.

8\.      Intellectual Property Ownership.

a.       Provider IP. Customer acknowledges that, as between Customer and Provider, Provider owns all right, title, and interest, including all intellectual property rights, in and to the Provider IP and, with respect to Third-Party Products, the applicable third-party providers own all right, title, and interest, including all intellectual property rights, in and to the Third-Party Products.

b.      Customer Data. Provider acknowledges that, as between Provider and Customer, Customer owns all right, title, and interest, including all intellectual property rights, in and to the Customer Data. Customer hereby grants to Provider a non-exclusive, royalty-free, worldwide license to reproduce, distribute, and otherwise use and display the Customer Data and perform all acts with respect to the Customer Data as may be necessary for Provider to make the Service available to Customer, and a non-exclusive, perpetual, irrevocable, royalty-free, worldwide license to reproduce, distribute, modify, and, depending on Service as outlined in Documentation, otherwise use and display Customer Data incorporated within the Aggregated Statistics.  Customer Data shall be maintained by Provider and made available to Customer as provided for in the Documentation. NOTE: The use of Aggregated Statistics and/or Customer Data by Third-Party Products is governed by the relevant agreements Customer has with the providers of such Third-Party Products.

c.       Feedback. If Customer or any of its employees or contractors sends or transmits any communications or materials to Provider by mail, email, telephone, or otherwise, suggesting or recommending changes to the Provider IP, including without limitation, new features or functionality relating thereto, or any comments, questions, suggestions, or the like ("**Feedback**"), Provider is free to use such Feedback irrespective of any other obligation or limitation between the Parties governing such Feedback. Customer hereby assigns to Provider on Customer's behalf, and on behalf of its employees, contractors and/or agents, all right, title, and interest in, and Provider is free to use, without any attribution or compensation to any party, any ideas, know-how, concepts, techniques, or other intellectual property rights contained in the Feedback, for any purpose whatsoever, although Provider is not required to use any Feedback.

9\.      Limited Warranty and Warranty Disclaimer.

a.       Provider warrants, to the Customer only, that the Service will conform in all material respects to the specifications set forth in the Documentation, when accessed and used in accordance with the Documentation. THE FOREGOING LIMITED WARRANTY DOES NOT APPLY, AND PROVIDER STRICTLY DISCLAIMS ALL WARRANTIES, WITH RESPECT TO ANY THIRD-PARTY PRODUCTS.

b.      EXCEPT FOR THE LIMITED WARRANTY SET FORTH IN SECTION 9 (a) THE SERVICE IS PROVIDED "AS IS," “WHERE IS,” AND “AS AVAILABLE,” AND PROVIDER HEREBY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. PROVIDER SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ALL WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE. PROVIDER MAKES NO WARRANTY OF ANY KIND THAT THE SERVICE, OR ANY PRODUCTS OR RESULTS OF THE USE THEREOF, WILL MEET CUSTOMER'S OR ANY OTHER PERSON'S REQUIREMENTS, OPERATE WITHOUT INTERRUPTION, ACHIEVE ANY INTENDED RESULT, BE COMPATIBLE OR WORK WITH ANY SOFTWARE, SYSTEM, OR OTHER SERVICES, OR BE SECURE, ACCURATE, COMPLETE, FREE OF HARMFUL CODE, OR ERROR FREE.

10\.  Indemnification.

a.       Provider Indemnification.

(i)                 Provider shall indemnify, defend, and hold harmless Customer from and against any and all losses, damages, liabilities, costs (including reasonable attorneys' fees) ("**Losses**") incurred by Customer resulting from any third-party claim, suit, action, or proceeding ("**Third-Party Claim**") that the Service, or any use of the Service in accordance with this Agreement, infringes or misappropriates such third party's US intellectual property rights/US patents, copyrights, or trade secrets, provided that Customer promptly notifies Provider in writing of the claim, cooperates with Provider, and allows Provider sole authority to control the defense and settlement of such claim.

(ii)              If such a claim is made or threatened, Provider may, at Provider's sole discretion, (A) modify or replace the Services, or component or part thereof, to make it non-infringing, or (B) obtain the right for Customer to continue use of the Service. If Provider determines that neither alternative is reasonably available, Provider may terminate this Agreement, in its entirety or with respect to the affected component or part, effective immediately on written notice to Customer.

(iii)            This Section 10(a) will not apply to the extent that the alleged infringement arises from: (A) use of the Service in combination with data, software, hardware, equipment, or technology not provided by Provider or authorized by Provider in writing; (B) modifications to the Service not made by Provider; (C) Customer Data; or (D) Third-Party Products.

b.      Customer Indemnification. Customer shall indemnify, hold harmless, and, at Provider's option, defend Provider from and against any Losses resulting from any Third-Party Claim that the Customer Data, or any use of the Customer Data in accordance with this Agreement, infringes or misappropriates such third party's US intellectual property rights and any Third-Party Claims based on Customer's or any Authorized User's (i) negligence or willful misconduct; (ii) use of the Service in a manner not authorized by this Agreement; (iii) use of the Service in combination with data, software, hardware, equipment, or technology not provided by Provider or authorized by Provider in writing; or (iv) modifications to the Service not made by Provider, provided that Customer may not settle any Third-Party Claim against Provider unless Provider consents to such settlement, and further provided that Provider will have the right, at its option, to defend itself against any such Third-Party Claim or to participate in the defense thereof by counsel of its own choice.

c.       Sole Remedy. THIS SECTION 10 SETS FORTH CUSTOMER'S SOLE REMEDIES AND PROVIDER'S SOLE LIABILITY AND OBLIGATION FOR ANY ACTUAL, THREATENED, OR ALLEGED CLAIMS THAT THE SERVICES INFRINGE, MISAPPROPRIATE, OR OTHERWISE VIOLATE ANY INTELLECTUAL PROPERTY RIGHTS OF ANY THIRD PARTY.

11\.  Limitations of Liability. IN NO EVENT WILL PROVIDER BE LIABLE UNDER OR IN CONNECTION WITH THIS AGREEMENT UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, AND OTHERWISE, FOR ANY: (a) CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, ENHANCED, OR PUNITIVE DAMAGES; (b) INCREASED COSTS, DIMINUTION IN VALUE OR LOST BUSINESS, PRODUCTION, REVENUES, OR PROFITS; (c) LOSS OF GOODWILL OR REPUTATION; (d) USE, INABILITY TO USE, LOSS, INTERRUPTION, DELAY, OR RECOVERY OF ANY DATA, OR BREACH OF DATA OR SYSTEM SECURITY; OR (e) COST OF REPLACEMENT GOODS OR SERVICES, IN EACH CASE REGARDLESS OF WHETHER PROVIDER WAS ADVISED OF THE POSSIBILITY OF SUCH LOSSES OR DAMAGES OR SUCH LOSSES OR DAMAGES WERE OTHERWISE FORESEEABLE. IN NO EVENT WILL PROVIDER'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, AND OTHERWISE EXCEED THE TOTAL AMOUNTS PAID TO PROVIDER UNDER THIS AGREEMENT IN THE TWELVE-MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

12\.   Termination. In addition to any other express termination right set forth in this Agreement:

a.       Either Party may terminate this Agreement upon thirty (30) days written notice to the other Party.

b.      Provider may also terminate this Agreement immediately upon written notice to Customer if Customer:

(i)                 fails to pay any amount when due hereunder, or otherwise fails to comply with any provision this Agreement, and such failure continues more than ten (10) days after Provider's delivery of written notice thereof; or

(ii)              becomes insolvent, files or has filed against it, a petition for voluntary or involuntary bankruptcy, makes a general assignment for the benefit of its creditors, or applies for or has appointed a receiver, trustee, custodian, or similar agent to take charge of or sell any material portion of Customer’s business or property.

c.       Effect of Expiration or Termination. Upon expiration or earlier termination of this Agreement, Customer shall immediately discontinue use of the Service and, without limiting Customer's obligations under Section 7, Customer shall delete, destroy, or return all copies of the Provider IP and certify in writing to the Provider that the Provider IP has been deleted or destroyed. No expiration or termination will affect Customer's obligation to pay all Fees that may have become due before such expiration or termination or entitle Customer to any refund.  Upon expiration or earlier termination of this Agreement, Provider shall also return or destroy Customer Data as provided for herein and in the Documentation.

d.      Survival. This Section 12(d) and Sections 6, 7, 8, 9b, 10, 11, and 13 shall survive any termination or expiration of this Agreement. No other provisions of this Agreement survive the expiration or earlier termination of this Agreement.

13\.  Miscellaneous.

a.       Entire Agreement. This Agreement, together with any other documents incorporated herein by reference, constitutes the sole and entire agreement of the Parties with respect to the subject matter of this Agreement and supersedes all prior and contemporaneous understandings, agreements, and representations and warranties, both written and oral, with respect to such subject matter. In the event of any inconsistency between the statements made in the body of this Agreement, and any other documents incorporated herein by reference, this Agreement shall take precedence.

b.      Notices. All notices, requests, consents, claims, demands, waivers, and other communications hereunder (each, a "**Notice**") must be in writing and addressed to the Parties at the addresses set forth on the Service Order (or to such other address that may be designated by the Party giving Notice from time to time in accordance with this Section). All Notices must be delivered by email (with confirmation of transmission), or certified or registered mail (in each case, return receipt requested, postage pre-paid). Except as otherwise provided in this Agreement, a Notice is effective only: (i) upon receipt by the receiving Party; and (ii) if the Party giving the Notice has complied with the requirements of this Section.

c.       Force Majeure. In no event shall Provider be liable to Customer, or be deemed to have breached this Agreement, for any failure or delay in performing its obligations under this Agreement, if and to the extent such failure or delay is caused by any circumstances beyond Provider's reasonable control, including but not limited to acts of God, flood, fire, earthquake, explosion, war, terrorism, invasion, riot or other civil unrest, strikes, labor stoppages or slowdowns or other industrial disturbances, or passage of law or any action taken by a governmental or public authority, including imposing an embargo.

d.      Amendment and Modification.  This Agreement may be modified or amended at any time by Provider.  The current version of the Agreement shall be available at <https://cc.docs.landis.cloud/appendix/terms>.  Provider shall make reasonable efforts to notify Customer of any material changes to the Agreement but shall not be obligated to do so.  Your continued access to and use of the Service shall constitute your acceptance of any amendment or modification to this Agreement.&#x20;

e.       Waiver. Except as otherwise set forth in this Agreement, (i) no failure to exercise, or delay in exercising, any rights, remedy, power, or privilege arising from this Agreement will operate or be construed as a waiver thereof, and (ii) no single or partial exercise of any right, remedy, power, or privilege hereunder will preclude any other or further exercise thereof or the exercise of any other right, remedy, power, or privilege.

f.        Severability.  In case any provision in this Agreement shall be invalid, illegal or unenforceable in any jurisdiction, such provision shall, as to such jurisdiction be ineffective to the extent of such invalidity, illegality or unenforceability without affecting the validity, legality and enforceability of the remaining provisions; and the invalidity of a particular provision in a particular jurisdiction shall not invalidate such provision in any other jurisdiction.

g.      Governing Law; Submission to Jurisdiction. This Agreement is governed by and construed in accordance with the internal laws of the Commonwealth of Pennsylvania without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the Commonwealth of Pennsylvania. Any legal suit, action, or proceeding arising out of or related to this Agreement or the licenses granted hereunder will be instituted exclusively in the federal courts of the United States or the courts of the State of Pennsylvania in each case located in the County of Lancaster, and each Party irrevocably submits to the jurisdiction of such courts in any such suit, action, or proceeding.

h.      Assignment. Customer may not assign any of its rights or delegate any of its obligations hereunder, in each case whether voluntarily, involuntarily, by operation of law or otherwise, without the prior written consent of Provider. Any purported assignment or delegation in violation of this Section will be null and void. No assignment or delegation will relieve the assigning or delegating Party of any of its obligations hereunder. This Agreement is binding upon and inures to the benefit of the Parties and their respective permitted successors and assigns.

i.        Export Regulation. Customer shall comply with all applicable federal laws, regulations, and rules, and complete all required undertakings (including obtaining any necessary export license or other governmental approval), that prohibit or restrict the export or re-export of the Service or any Customer Data outside the US.

j.        Equitable Relief. Each Party acknowledges and agrees that a breach or threatened breach by such Party of any of its obligations under Section 7 or, in the case of Customer, Section 3(c), would cause the other Party irreparable harm for which monetary damages would not be an adequate remedy and agrees that, in the event of such breach or threatened breach, the other Party will be entitled to equitable relief, including a restraining order, an injunction, specific performance, and any other relief that may be available from any court, without any requirement to post a bond or other security, or to prove actual damages or that monetary damages are not an adequate remedy. Such remedies are not exclusive and are in addition to all other remedies that may be available at law, in equity, or otherwise.


