Client zone rules
Appendix No 2 to the Agreement about Broker IT solution usage, terms and conditions
IT solution
1.Client zone is the IT solution designed by the Broker shall cover the software, databases, technical means, connections and links with databases of third parties (Insurers’, etc.) necessary for their maintenance. The purpose of the Client zone is to offer the possibility and means to Customers for independent supplementing and control of information about the properties insured or intended to by insured by the Customer, to monitor the insurance coverage of such properties, to fill in the information about the available insurance contracts (policies) and to conclude new insurance contracts. In the Client zone the Customer can get access to the data available to Aon concerning the insurance contracts concluded on behalf of the Customer or insurance contracts indicating the Customer as the beneficiary, other related information legitimately processed by Aon. The Customer has the possibility to independently enter, save and process other data about his enterprise, its assets and other information that is made available on the Client zone. The Customer may, through intermediation of Aon, conclude, extend and renew the proposed insurance contracts with the proposed insurance companies as well as receive, store and process the information about the insurance contracts concluded on behalf and (or) for the benefit of the Customer or carry out other actions which are available on the Client zone.
Technical requirements
2. The Customer has the right to use the IT solution only if the computer security measures available to the Customer guarantee that the IT solution will be used in safe manner, without disclosing any data to the unauthorised parties and without creating any conditions for unauthorised use of IT solutions by such unauthorized parties. To that end the Customer must observe all necessary security measures in his computer system. Each Party will be held liable for all consequences and losses resulting from insufficient security of its computer system.
Users of IT Solution
3. The right to use the IT solution is granted only to the employees who are authorised by the Customer and have
personal identification tools assigned by the Broker – the data for connecting to the IT solution: a login name
and passwords (Login credentials). The Broker uses its best endeavours to additionally provide
the Customer with the possibility to access the IT solution using other means of Customer’s authentication
(e-banking authentication, e-signature, mobile signature and/or other, if such a provided), through banks and/or
other institutions providing authentication services to the Broker (Third Party Authenticators).
In such cases the Login credentials will not be issued to the Customer’s authorized employees, unless otherwise
agreed by the Parties. The Broker is entitled to terminate and/or limit rights to access the IT solution using
Third Party Authenticators at any time. The responsible employee of the Customer specified in Annexes to the
Agreement will be notified no later than 10 days in advance of such termination or limitations, and, if so
requested by the Customer, the Login credentials will be issued to the respective Customer’s employees.
4. For the purpose of assigning the Login credentials or access by means of Third Party Authenticators the Broker
will send Login credentials or access confirmation by e-mail directly to the Customer’s employees indicated by
the Customer no later than within 2 (two) business days of the day of receipt of the Customer’s request. The
request for assigning, changing or cancelling the means of access to the IT Solution has to indicate the forenames,
surnames, personal ID number and contact details (phone and e-mail address) of the Customer’s employees to whom
the assigning, change or cancellation of the means of access is requested.
5. The Customer must guarantee that the Customer’s employees to whom, on request of the Customer, the valid Login
credentials have been assigned rights to access the IT solution using Third Party Authenticators have been granted
shall adhere to the requirements of all conditions of the use of the IT solution and related legal acts. To that
end the Customer has to properly disclose and explain the rules of the use of the IT solution to his employees.
The Broker, on his part, must also guarantee the confidentiality of the Login credentials of the Customer’s
employees stored in the Broker’s IT system and (or) held in possession of the Broker’s employees.
6. Where necessary (in order to ensure the secure functioning of the IT solution and of the data stored in it
and in similar cases) the Broker has the right to change the Login credentials, promptly notifying about their
change the person to whom the Login credentials subject to the changed had been assigned.
7. The Customer’s employees to whom the Login credentials had been assigned must guarantee the safety and
confidentiality of such data. The Customer remains solely responsible for the use of the Third Party Authenticators.
The Login credentials and/or means or data used by the Third Party Authenticators may not be disclosed to third
parties. A person who uses his Login credentials and/or the Third Party Authenticators to connect to the IT solution
is not entitled to allow other persons to use the IT solution or to allow unauthorised persons to access the data
provided by the IT solution. Connection to the IT solution using other person’s Login credentials or other person’s
Third Party Authenticators is prohibited.
8. If there is a threat that the Login credentials and/or means or data used by the Third Party Authenticators
might have become known to unauthorised parties, the respective Customer’s employee, must promptly inform the
responsible employee of the Customer specified in Annexes to the Agreement, who must notify the Broker without
undue delay about the change of the Login credentials and temporary suspension of validity of the existing Login
credentials and/or suspension access rights using respective person’s Third Party Authenticators.
9. The Customer has the right to request at any time the cancellation or change of validity of the Login
credentials assigned to the employees specified by the Customer. The Broker has the right to cancel the validity
of the Login credentials or rights to access the IT solution using Third Party Authenticators for persons who
violate these Client zone rules. The responsible employee of the Customer specified in Annexe No 1 to the
Agreement will be notified by the Broker in case of aforementioned cancellation of the Login credentials
validity and/or rights to access the IT solution using Third Party Authenticators immediately after such suspension.
10. If the Broker suspects that connection of one or several IT solution users to the IT solution is unsafe or
poses threat to the security of the functioning of the IT solution or data stored in it, the validity of the
Login credentials of aforesaid IT solution users and/or rights to access the IT solution using Third Party
Authenticators may be temporarily suspended by the Broker until investigating the circumstances that gave rise
to the suspicions and, where appropriate, until eliminating the threats for the functioning of the IT solution
or security of data stored in it. The responsible employee of the Customer specified in Annexes to the Agreement
will be notified by the Broker in case of such suspension of the Login credentials and/or rights to access the
IT solution using Third Party Authenticators.
11. The Login credentials are valid until their change, cancellation of heir validity, or until termination of the Agreement.
Use of the IT solution
12. The IT solution may be used only for the performance of actions indicated in Article 1 above using the means
and tools provided by the IT solution, and in accordance with rules and criteria set by the IT solution. No
other actions using the IT solution is to be carried out by the Customer. The Customer’s employees have the
right to connect to the IT solution only from the IP addresses agreed between the Parties. It is prohibited to
connect to the IT solution using other IP addresses, unless the Parties have agreed otherwise. By signing this
Agreement the Customer confirms his awareness that if the opportunity to connect to the IT solution from any IP
address is provided, the Broker’s possibilities to ensure the security of such connection and of the functioning
of the IT solution considerably worsen. Where authorised employees of the Customer on agreement of the Parties
are authorised to connect to the IT solution from any IP address, the Customer undertakes to ensure the security
of such connection and shall assume all risk and liability for damage or violations of law resulting from
connections using the Login credentials assigned to the Customer’s employees. The IP address limitations does
not apply to access to the IT solution using Third Party Authenticators.
13. Data obtained using the IT solution may be used only for proposes specified in the Agreement.
14. The Customer and the Customer’s employees must ensure the confidentiality of data obtained using the IT
solution and the protection and processing of the natural person’s data obtained using the IT solution, in
accordance with the procedure laid down by the Agreement and requirements of applicable laws.
15. All property rights of the authors to the software, which constitutes the IT solution, and rights of the
maker of databases made by the Broker to ensure the operation of the IT solution belong to the Broker and/or other
Aon group companies. During the term of the Agreement the Customer has the right to use the IT solution
without additional fee, in manner and to the limited extent laid down in the Agreement.
Information notice to the Customer’s employees using the IT solution
16. UADBB Aon Baltic Estonian branch, registration No. 11915671, registered office aadress: Telliskivi 60/1-63, Tallinn 10412, Estonia, will be processing personal data of Customer’s employees for purposes of ensuring their access to the IT Solution. The personal data of Customer’s employees that will be processed for this purpose is name, surname, position, phone number, e-mail address, IP address. The basis for such processing is the contractual relationship between the Broker (Aon) and the Customer. This data will be stored until the Customer’s employee or the Customer employer notify the Broker (Aon) that access to the IT Solution is no longer required. Customer’s employee has the right to request from the Broker (Aon) access to and rectification or erasure of his or hers personal data or restriction of processing or to object to processing as well as to receive the data in a structured, commonly used and machine-readable format. Customer’s employee also has the right to lodge a complaint with a local supervisory authority. If the Customer’s employee chooses to access IT solution by using services of third parties (e.g. Third Party Authenticators), then personal data of such employee will be transferred to this third party to the extent necessary to provide the Customer’s employee with the access.