Partner Platform
Partner Security, Fraud and Liability Provisions
1. Partner Systems and Access Channels
Where the Partner provides or controls any website, application, portal, single sign-on service, authentication process, hyperlink, API, integration, member database, email communication, SMS communication or other system through which a Member accesses or is directed to the WeMAD Platform (Partner Environment), the Partner is responsible for the security, integrity and proper operation of the Partner Environment.
The Partner must take reasonable and appropriate technical and organisational measures to protect the Partner Environment and Member information against unauthorised access, compromise, misuse, interference, loss, modification, disclosure, credential theft, phishing, account takeover and other fraudulent or malicious activity.
2. Allocation of Security Responsibility
Each party is responsible for the systems, infrastructure, credentials, authentication processes, personnel and information within its possession or control.
WeMAD is responsible for security controls applicable to the WeMAD Platform to the extent those systems and controls are within WeMAD's possession or control.
The Partner is responsible for security controls applicable to the Partner Environment to the extent those systems and controls are within the Partner's possession or control.
Neither party assumes responsibility for a security failure occurring solely within systems controlled by the other party.
3. Partner Authentication and Member Access
Where Members are authenticated, identified or granted access to WeMAD through a Partner-controlled system, including single sign-on or another federated authentication mechanism, the Partner is responsible for ensuring that:
- only authorised Members are authenticated;
- authentication credentials are appropriately protected;
- access credentials and authentication tokens are securely generated, stored and transmitted;
- terminated or ineligible Members have their access revoked promptly;
- authentication systems incorporate security controls appropriate to the risk;
- Member information supplied to WeMAD is accurate and authorised; and
- Partner systems are reasonably protected against account takeover, credential theft, session hijacking, phishing and unauthorised access.
WeMAD is entitled to rely on an authentication or Member validation received from the Partner unless WeMAD knows, or reasonably ought to know, that the authentication or validation is invalid or compromised.
4. Security Incidents
Each party must notify the other as soon as reasonably practicable after becoming aware of an actual or reasonably suspected security incident that may materially affect:
- the WeMAD Platform;
- the Partner Environment;
- Member Accounts;
- Gift Cards;
- Member personal information;
- authentication credentials;
- transaction information; or
- the security of the integration between the parties.
The affected party must promptly investigate the incident, preserve relevant evidence and take reasonable steps to contain and remediate the incident.
The parties must reasonably cooperate in investigating the source, cause, scope and financial impact of the incident.
Neither party's cooperation with an investigation constitutes an admission of liability.
5. Evidence and Audit Records
Each party must maintain reasonable records relevant to authentication, access and transactions occurring through systems within its control.
Subject to applicable privacy, confidentiality and security requirements, each party must provide the other with information reasonably required to investigate suspected fraud or a security incident, including relevant:
- authentication records;
- access logs;
- timestamps;
- transaction identifiers;
- IP and device information where lawfully collected;
- SSO or authentication events;
- security alerts;
- Member communications; and
- incident investigation findings.
The purpose of this information exchange is to enable the parties to determine, on the available evidence, where and how the incident occurred and appropriately allocate responsibility.
6. Fraud and Unauthorised Transactions
The Partner acknowledges that WeMAD must not automatically bear the financial cost of fraud, unauthorised transactions, Gift Card theft or Member reimbursement merely because the affected transaction was processed or fulfilled through the WeMAD Platform.
Responsibility for a Fraud Loss will be determined having regard to the cause of the loss and the systems, conduct or failure that caused or materially contributed to it.
Where a Fraud Loss results from or is materially contributed to by:
- compromise of the Partner Environment;
- unauthorised access originating through the Partner Environment;
- compromised Partner authentication or SSO;
- compromised Member credentials within the Partner Environment;
- phishing or fraudulent communications originating from or facilitated through compromised Partner systems;
- unauthorised disclosure of Member information by the Partner;
- failure by the Partner to implement the security obligations required under this Agreement;
- failure by the Partner to revoke or restrict unauthorised Member access;
- negligent or wrongful acts or omissions of the Partner's employees, contractors or service providers; or
- another security failure within the Partner's possession or control,
the resulting Fraud Loss will be the responsibility of the Partner to the extent that the Partner's act, omission or security failure caused or contributed to that loss.
7. Definition of Fraud Loss
Fraud Loss means reasonable and properly substantiated loss directly arising from fraud, unauthorised access or a security incident, including, where applicable:
- the value of fraudulently obtained Gift Cards;
- amounts reasonably reimbursed to affected Members;
- payment reversals and chargebacks;
- unrecoverable supplier costs;
- reasonable investigation and incident-response costs;
- reasonable forensic and remediation costs; and
- other direct losses reasonably incurred in responding to the incident,
to the extent caused or contributed to by the relevant party's breach, negligence, wrongful act, omission or security failure.
Fraud Loss does not include remote, speculative or punitive loss.
8. Reimbursement Decisions
Neither party may unreasonably require the other party to reimburse a Member or third party for a suspected Fraud Loss before reasonable investigation of the incident, except where reimbursement is required by law or immediate action is reasonably required to mitigate further loss.
Where one party elects to make a voluntary or goodwill reimbursement without the other party's prior agreement, that reimbursement does not automatically create a liability for the other party.
Where reimbursement is legally required or reasonably necessary and the investigation establishes that the loss was caused or materially contributed to by the Partner Environment, the Partner must reimburse WeMAD for the Partner's proportionate share of that loss.
9. Indemnity
To the extent permitted by law, the Partner indemnifies WeMAD and its officers, employees and contractors against Fraud Loss and third-party claims to the extent arising from:
- a breach by the Partner of its security, privacy, confidentiality or authentication obligations under this Agreement;
- fraud, negligence or wrongful conduct by the Partner or its personnel;
- unauthorised access to or compromise of the Partner Environment;
- unauthorised disclosure of Member information by the Partner; or
- the acts or omissions of a contractor or service provider engaged by the Partner in connection with the Partner Environment.
The indemnity is reduced proportionately to the extent that an act, omission, breach or security failure of WeMAD caused or contributed to the relevant loss.
10. WeMAD Platform Compromise
Correspondingly, where an investigation establishes that a Fraud Loss was caused by a security failure occurring within systems exclusively controlled by WeMAD, responsibility for that loss will be determined having regard to WeMAD's obligations under this Agreement and applicable law.
The Partner is not responsible for a Fraud Loss merely because its Members were affected where the Partner Environment did not cause or materially contribute to the incident.
11. Failure to Cooperate
If a party fails, without reasonable excuse, to provide logs, records or information reasonably necessary to investigate an incident within its systems, that failure may be taken into account when determining contractual responsibility for the resulting loss.
Nothing in this clause creates a presumption of liability solely because particular information is unavailable.
12. Continuing Security Obligations
The security, confidentiality, incident-response, evidence preservation, liability and indemnity provisions of this Agreement survive termination to the extent necessary to deal with an incident or claim arising from events occurring before termination.
