Addendum to the InCommon Participation Agreement for the InCommon/Duo Security Multi-Factor Authentication Service v. 8 October 2014 This InCommon/Duo Security Multi-Factor Authentication Service Addendum ("Addendum") is entered into between InCommon, LLC ("InCommon") and _____________________________________________________________ ("Subscriber") individually a "Party" and collectively the "Parties." Subscriber wishes to participate in the site license offering of the Duo Security Two Factor Authentication Service (“Service”) and to use associated software developed by Duo Security (“Software”) marketed and sold by the University Corporation for Advanced Internet Development (“Internet2”) and InCommon LLC under an agreement with Duo Security. The terms and conditions contained in this Addendum supplement and are in addition to the terms and conditions in the Participation Agreement (“Agreement”) between the Parties. In the event of a conflict between the Addendum and the Agreement as to the subject matter of this Addendum, the terms of the Addendum shall prevail; however, silence does not create a conflict. Therefore, in consideration of an annual fee of $_____________, which Subscriber commits to pay InCommon, the Parties agree as follows: A. Duo Security Account Identifier. For initial set up and activation, Subscriber's Duo Security "Duo Account ID" is listed below. Additional detail is described in section C. Duo Account ID: _____________________________________________________________ B. Scope of Participation. This Service is being offered to Subscribers on a site license basis and may be used by all of Subscriber’s end users subject to the scope of participation, which Subscriber has specified in the table below and subject to payment of the associated annual fees. The available scopes of participation are: FS=non-hospital faculty and staff only; FSS=non-hospital faculty, staff, and all registered students; HS=hospital staff only (includes hospital faculty), CA=Campus Associates or any combination of these scopes. For purposes of this Addendum, Campus Associates means individuals who work with the Subscriber but are not paid by the Subscriber as faculty or staff members and that are not otherwise covered under the Duo Security Addendum. Examples of Campus Associates include, but are not limited to, visiting staff members paid by their home institutions and unpaid volunteers or docents at a campus museum. Campus Associates do not include other large populations of individuals such as university alumni. To be eligible to add Campus Associates, Subscriber must also purchase non-hospital faculty and staff coverage. Approval to add Campus Associates is at InCommon's discretion, and is subject to acceptance by Duo Security. InCommon Duo Security Multifactor Service Addendum 1 of 5 List all Campus and Hospital units separately. IPEDS Total Student Count Scope of Service in Any or Combination: FS, FSS, HS, Hospital Bed Count CA 1. EXAMPLE UNIVERSITY MAIN CAMPUS 2. EXAMPLE UNIVERSITY HOSPITAL IPEDS Students: 45,000 Bed Count: 800 FS HS 1. 2. 3. 4. 5. Add more rows if necessary C. Two Factor Authentication Service. 1. Appointment of Administrators. Subscriber is responsible for the appointment and upkeep of Subscriber's administrators who are authorized to administer the Service on behalf of Subscriber. Subscriber accepts full and complete responsibility for the actions of all Subscriber administrators related to the Duo Security management system. Subscriber is also responsible for the removal of administrators who are no longer authorized to manage the Duo System on behalf of Subscriber. 2. Activation of Account on Duo Security System. Subscriber will initially establish a Duo Trial account at no charge, with a Duo Account ID as account identifier, which shall be used to manage its use of the system. Subscriber can establish and use a trial account at no charge and without signing an Addendum to do initial testing and set up of administrator accounts. Once Subscriber is ready for production use of the system, it will submit to InCommon a signed copy of this Addendum. InCommon will invoice Subscriber and notify Duo Security to enable the established account listed in section A above for production status, allowing the number of user accounts consistent with the scope of Subscriber's site license. D. Service and Restrictions. Subscriber agrees that: 1. InCommon, under agreement with Duo Security, shall provide the Service, including Software, to Subscriber for a one-year term (renewal described below) beginning with the Effective Date below. During the Term or otherwise, Subscriber shall not: (i) modify, disassemble, decompile or reverse engineer the Service, including Software, except to the extent that such restriction is expressly prohibited by law; (ii) share, rent, lease, loan, resell, sublicense, distribute or otherwise transfer the Service to any third party or use the Service to provide time sharing or similar services for any third party, understanding that for purposes of this subsection, Subscriber's faculty, staff, and students do not constitute a third party; (iii) make any copies of the Service; (iv) remove, circumvent, disable, damage or otherwise interfere with security-related features of the Service, features that prevent or restrict use or copying of any content accessible through the Service, or features that enforce limitations on use of the Service; or (v) delete the copyright and other proprietary rights notices on the Service or Software. 2. During the Term, InCommon, under agreement with Duo Security, grants Subscriber a non-exclusive, non-transferable, revocable license to use Software as follows: Subscriber may use the Software (i) for integration with its end users' computers or its website application services, and (ii) on mobile devices under the control and use of Subscriber or Subscriber's end users. The foregoing license under this Addendum is not a sale of the Software or any copy thereof, and Duo Security or its third party partners or suppliers retain all right, title, and interest in the Software (and any copy thereof). Any attempt by InCommon Duo Security Multifactor Service Addendum 2 of 5 Subscriber to transfer any of the rights, duties or obligations hereunder, except as expressly provided for in this Addendum, is void. Duo Security reserves all rights not expressly granted under this Addendum and Agreement. 3. Ownership. All right, title, and interest in the Service, the Software and in any ideas, know-how, code, derivative works or intellectual property associated therewith, including without limitation any enhancements or modifications made to the Service or the Software by any person (however employed or associated, including you) shall at all times remain solely and exclusively the property of Duo Security. 4. Proprietary Marks. Except as specifically authorized by Duo Security in writing, Subscriber shall not alter, change or remove from the Service any trademark, other proprietary mark or proprietary rights notice. 5. Support. Subscriber’s end-user support is to be provided by Subscriber. Duo Security provides second tier customer support to Subscriber’s Service administrators but does not provide support to Subscriber’s end-users. Duo Security has no obligation to provide professional services, upgrades, modifications, or new releases to the Service under this Agreement. Duo Security may voluntarily provide some or all of these items; should Duo Security do so, any such action shall not be considered a waiver of this provision. E. F. Term and Termination. 1. Term. This Addendum is effective upon the Effective Date stated below and shall continue for a period of one year ("Addendum Term"). If Subscriber or InCommon chooses to terminate its general InCommon Participation as defined in the Participation Agreement, this Addendum will continue to remain effective throughout the current Addendum Term along with any necessary provisions in the Participation Agreement. Subscriber will not be able to renew this Addendum unless Subscriber is an active InCommon Participant. 2. Renewal and Termination. This Addendum will automatically renew for successive, additional one-year terms (each a “renewal term”), except as set forth below. This Addendum will terminate at the end of the initial one year term or the then-current renewal term (the “Then-Current One-year term”), as the case may be, if either party gives the other party written notice of termination of this Addendum at least 90 days prior to the expiration of the Then-Current One-year term or within 30 days from the due date of the first invoice for the upcoming renewal term, whichever is later. Renewal invoice will be issued 30 days prior to the renewal date. In addition, if Subscriber does not pay to InCommon the full amount invoiced for the upcoming renewal term as described below, this Addendum shall also terminate and shall not renew and InCommon will request that Duo Security disable all user accounts and administrator access to the Duo Security system. InCommon will make reasonable efforts to contact Subscriber prior to disabling system for non-payment but it is Subscriber’s responsibility to pay invoices in a timely manner. For each renewal term, payment of the first invoice for such renewal term shall be deemed to confirm Subscriber’s acceptance of the renewal of this Addendum for such renewal term at the then-current annual fees and other charges. 3. Cessation of Services. InCommon shall notify Subscriber if it elects to discontinue operation of the Service with at least ninety (90) days notice prior to such discontinuation. Fees and Payment. 1. Invoices and Payment. Initial invoice will be issued immediately upon the signing of this Addendum. Subscriber will pay all valid invoices within 60 days from the due date of the invoice. If after 30 days from the due date of the invoice account remains in arrears, InCommon may suspend Subscriber’s use of the Service. 2. Fees. For each renewal term, the then-current fee schedule as then published on the InCommon website (incommon.org/duo) will apply to determine the amount of the annual and other payments that must be made by Subscriber to InCommon each year during such renewal term. InCommon Duo Security Multifactor Service Addendum 3 of 5 3. Scope of Fees and Additional Fees. The annual site license fee listed above covers all use of the Duo Security system for Internet-based use of the system as well as off-line One Time Password use of the system. On-line authentication using either SMS or Telephony requires that Subscriber maintain a pool of telephony credits associated with its accounts that are charged directly by Duo Security, based on the type of on-line non-Internet based communication and the location of the device, as documented on Duo Security's website. The preferred method of replenishing the telephony credit pool is to provide Duo Security with a credit card account that will be used to charge for each end user's telephony credit pool. Otherwise, the Subscriber will be required to make payment directly to Duo Security in advance and monitor and maintain an adequate telephony credit pool in order for telephonybased authentication to be available for Subscriber’s user accounts. 4. Refunds. Given the term of this Addendum and the ease of trial accounts for testing, there are no refunds for any fees collected in association with this Addendum. G. Disclaimers and Limitation of Liability. The provisions on disclaimer and limitation on liability contained in section 11 of the Agreement apply to this Addendum. For purposes of section 11, Duo Security is considered a third party service provider. H. Remedy 1. Injunctive Relief. The Parties acknowledge that a breach of this Addendum may result in irreparable harm to either Party that cannot adequately be redressed by compensatory damages. Accordingly, in addition to any other legal remedies that may be available, either Party may seek an injunctive order against a breach or threatened breach of the Addendum. I. Miscellaneous 1. Entire Agreement. This Addendum, along with the Participation Agreement, is the entire agreement between the Parties, superseding all other agreements that may exist with respect to the subject matter. Section headings are for reference and convenience only and are not part of the interpretation of the Addendum. 2. Waiver. A Party’s failure to enforce a provision of this Addendum does not waive the Party’s right to enforce the same provision later or right to enforce any other provision of this Addendum. To be effective, all waivers must be both in writing and signed by the Party benefiting from the waived provision. 3. Rights of Third Parties. Duo Security is an express third party beneficiary of Subscriber’s obligations and warranties in the Participation Agreement and this Addendum. J. Definitions 1. "Services" mean the set of two factor authentication services operated and provided by Duo 2. K. Security and marketed and sold by InCommon pursuant to the Reseller Agreement. “Software” means all Duo Security proprietary software utilized in providing the Service to you, including, without limitation, (a) all software integrated with Subscriber's SSL VPN, Unix operating system, and/or web application, and (b) all mobile device applications. Effective Date: Each of the Parties has agreed to the terms and conditions set forth in this Addendum as evidenced by their signatures below. This Addendum comes into effect as of the date of the latest signature (the "Effective Date"). InCommon Duo Security Multifactor Service Addendum 4 of 5 Subscriber InCommon Signature Signature Date Date Print Name Print Name Title Title InCommon Duo Security Multifactor Service Addendum 5 of 5