16.12.2012 Views

Terms of Use for Porsche Partner Network (PPN)

Terms of Use for Porsche Partner Network (PPN)

Terms of Use for Porsche Partner Network (PPN)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong><br />

<strong>for</strong><br />

<strong>Porsche</strong> <strong>Partner</strong> <strong>Network</strong> (<strong>PPN</strong>)<br />

Version 2.4 Date: 26 Jan. 06<br />

This version replaces all prior versions <strong>of</strong> this document.<br />

Dr. Ing. h.c. F. <strong>Porsche</strong> AG<br />

(hereinafter “<strong>Porsche</strong>”)<br />

<strong>Porsche</strong>platz 1<br />

70435 Stuttgart<br />

GERMANY<br />

Page 1 <strong>of</strong> 6


Preamble<br />

<strong>PPN</strong> is a service infrastructure <strong>of</strong> <strong>Porsche</strong> that allows <strong>Use</strong>rs <strong>of</strong> <strong>Partner</strong> Organizations to access<br />

specific IT Systems <strong>of</strong> <strong>Porsche</strong> using a secure connection over the Internet. The degree <strong>of</strong> access<br />

to these systems depends on the particular access rights assigned to the individual <strong>Use</strong>r. <strong>Porsche</strong><br />

aims at providing its <strong>Partner</strong> Organizations with an easy to use and cost effective way <strong>for</strong><br />

electronic communication and data provision.<br />

<strong>Porsche</strong> as well as its <strong>Partner</strong> Organizations are required to use <strong>PPN</strong> in a responsible way. This<br />

relates especially to IT security as sensitive in<strong>for</strong>mation and functions will be <strong>of</strong>fered over this<br />

infrastructure. <strong>PPN</strong> related in<strong>for</strong>mation like <strong>Use</strong>r account in<strong>for</strong>mation (<strong>PPN</strong> Certificates,<br />

<strong>Use</strong>rnames and passwords) and administrational processes are to be treated confidentially.<br />

1. Object and Scope <strong>of</strong> the Document<br />

The <strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> describe the rules and responsibilities <strong>for</strong> authorized <strong>Porsche</strong><br />

Importers and authorized <strong>Porsche</strong> Dealers using the <strong>PPN</strong> to access in<strong>for</strong>mation and business<br />

functions on <strong>Porsche</strong> IT Systems. They are binding <strong>for</strong> any organization whose employees or<br />

other agents use the <strong>PPN</strong> no matter <strong>for</strong> which purpose.<br />

2. Definition <strong>of</strong> <strong>Terms</strong><br />

Account In<strong>for</strong>mation <strong>Use</strong>rname, Password and <strong>PPN</strong> Certificate required to access <strong>PPN</strong> as an<br />

authorized <strong>Use</strong>r.<br />

<strong>PPN</strong> Certificate A <strong>PPN</strong> Certificate in this context is an electronic ID card downloaded to a<br />

<strong>Partner</strong> Organization’s PC that establishes the credentials <strong>of</strong> a <strong>Use</strong>r<br />

when opening a <strong>PPN</strong> connection. It is issued by the certification authority<br />

<strong>of</strong> <strong>Porsche</strong>.<br />

<strong>Partner</strong> Organization Authorized Dealer, Workshop or other partner that is acknowledged by<br />

<strong>Porsche</strong> to be part <strong>of</strong> the <strong>Porsche</strong> Sales Organization.<br />

<strong>PPN</strong> <strong>PPN</strong> is the short <strong>for</strong>m <strong>of</strong> <strong>Porsche</strong> <strong>Partner</strong> <strong>Network</strong>, the Data <strong>Network</strong><br />

connecting <strong>Partner</strong> Organizations in the <strong>Porsche</strong> Sales Organization to<br />

relevant <strong>Porsche</strong> IT Systems.<br />

<strong>PPN</strong> Coordinator The <strong>PPN</strong> Coordinator is located at the <strong>Partner</strong> Organization and<br />

administers all <strong>PPN</strong> <strong>Use</strong>r access at that or subordinate organizations.<br />

The <strong>PPN</strong> Coordinator’s actions in using the <strong>PPN</strong> Administration tool<br />

and/or granting <strong>PPN</strong> and other <strong>Porsche</strong> System access are binding on<br />

the <strong>Partner</strong> Organization.<br />

<strong>PPN</strong> Manager The <strong>PPN</strong> Manager is located at <strong>Porsche</strong> and manages all subordinate<br />

<strong>PPN</strong> Coordinators.<br />

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 2 <strong>of</strong> 6<br />

Version 2.4


3. <strong>PPN</strong> Utilization<br />

3.1. <strong>PPN</strong> may be used only <strong>for</strong> purposes related to the business <strong>of</strong> <strong>Porsche</strong>. The <strong>Partner</strong><br />

Organizations are liable <strong>for</strong> any abuse <strong>of</strong> the provided in<strong>for</strong>mation, systems and functions,<br />

especially against the interests <strong>of</strong> <strong>Porsche</strong> that occur in their sphere <strong>of</strong> influence or that are<br />

executed using a system or <strong>PPN</strong> account assigned to an employee or agent <strong>of</strong> the <strong>Partner</strong><br />

Organization. The <strong>Partner</strong> Organizations are also liable <strong>for</strong> damages that result <strong>of</strong> a violation<br />

<strong>of</strong> their due diligence.<br />

3.2. <strong>PPN</strong> may only be used by employees or other agents <strong>of</strong> <strong>Partner</strong> Organizations that have<br />

been assigned an individual <strong>Use</strong>r account by <strong>Porsche</strong>. Sharing <strong>of</strong> <strong>Use</strong>r accounts between<br />

multiple persons or the propagation <strong>of</strong> <strong>Use</strong>r account in<strong>for</strong>mation is not permitted.<br />

3.3. In<strong>for</strong>mation and functions provided by <strong>PPN</strong> may not be made available to any third parties<br />

by a <strong>Partner</strong> Organization <strong>for</strong> any reason. This does not include in<strong>for</strong>mation that was meant<br />

by <strong>Porsche</strong> to be distributed to certain interest groups by the <strong>Partner</strong> Organization.<br />

3.4. <strong>PPN</strong> certificates may only be used on <strong>of</strong>fice PCs <strong>of</strong> the <strong>Partner</strong> Organization. The <strong>Partner</strong><br />

Organization must ensure that its employees do not install <strong>PPN</strong> certificates on private or<br />

public PCs.<br />

3.5. <strong>Porsche</strong> may provide employees or agents <strong>of</strong> the <strong>Partner</strong> Organization with the ability to<br />

also access <strong>PPN</strong> from their private PCs without a <strong>PPN</strong> Certificate but with limited<br />

functionality that does not include business transactions. The <strong>Use</strong>r may not access <strong>PPN</strong><br />

from PCs available to the public.<br />

4. Duties <strong>of</strong> <strong>Partner</strong> Organizations<br />

4.1. The <strong>Partner</strong> Organization must ensure that every <strong>PPN</strong> <strong>Use</strong>r <strong>of</strong> its organization accesses<br />

<strong>PPN</strong> with the <strong>Use</strong>r account individually assigned to the <strong>Use</strong>r by <strong>Porsche</strong>.<br />

4.2. All <strong>Use</strong>rs must be in<strong>for</strong>med about their responsibilities using <strong>PPN</strong> by the <strong>PPN</strong> Coordinator.<br />

The IT Security Guidelines <strong>for</strong> <strong>PPN</strong> provided by <strong>Porsche</strong> must be distributed to every <strong>Use</strong>r.<br />

In the event that <strong>Use</strong>rs are not able to understand the document because <strong>of</strong> language<br />

problems, the <strong>Partner</strong> Organization must make sure that the content is personally explained<br />

to them.<br />

4.3. The <strong>Partner</strong> Organization must ensure that its <strong>PPN</strong> <strong>Use</strong>rs do not store their account<br />

in<strong>for</strong>mation at publicly accessible places, especially nearby their computers or in databases<br />

(also applicable <strong>for</strong> handhelds).<br />

4.4. The executive management <strong>of</strong> the <strong>Partner</strong> Organization must assign a <strong>PPN</strong> Coordinator to<br />

act on behalf <strong>of</strong> <strong>of</strong> the <strong>Partner</strong> Organization.<br />

4.5. The <strong>Partner</strong> Organization must ensure that the provision <strong>of</strong> <strong>Use</strong>r access rights to <strong>Porsche</strong><br />

systems does not conflict with the interests <strong>of</strong> either <strong>Porsche</strong> or the <strong>Partner</strong> Organization.<br />

Access rights administered by the <strong>Partner</strong> Organization should only be given to systems<br />

necessary <strong>for</strong> each <strong>Use</strong>r’s job description and must be removed in the event the <strong>Use</strong>r is no<br />

longer in a position that requires those access rights.<br />

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 3 <strong>of</strong> 6<br />

Version 2.4


4.6. In the event a <strong>Use</strong>r is no longer in a position at the <strong>Partner</strong> Organization in which it is<br />

necessary to have access to <strong>PPN</strong>, the <strong>Partner</strong> Organization (<strong>PPN</strong> Coordinator) must<br />

deactivate the account immediately. The request <strong>for</strong> deletion must be done within the online<br />

<strong>PPN</strong> Administration Tool. In the event there is no <strong>PPN</strong> Coordinator at the <strong>Partner</strong><br />

Organization, the <strong>Use</strong>r must request the deletion <strong>of</strong> the account directly by the responsible<br />

<strong>PPN</strong> Manager.<br />

4.7. <strong>PPN</strong> Certificates <strong>for</strong> PCs no longer used at the <strong>Partner</strong> Organisation must be immediately<br />

deactivated using the online <strong>PPN</strong> Administration tool. In the event there is no <strong>PPN</strong><br />

Coordinator at the <strong>Partner</strong> Organization, the <strong>Partner</strong> Organization must address the request<br />

directly to the responsible <strong>PPN</strong> Manager.<br />

4.8. Should the <strong>Partner</strong> Organization suspect that an unauthorized person has obtained account<br />

in<strong>for</strong>mation (e.g. Passwords, <strong>PPN</strong> Certificates) <strong>for</strong> <strong>PPN</strong>, the <strong>PPN</strong> Coordinator <strong>of</strong> the <strong>Partner</strong><br />

Organization must request a new password and/or certificate using the online <strong>PPN</strong><br />

Administration Tool. In the event there is no <strong>PPN</strong> Coordinator at the <strong>Partner</strong> Organization,<br />

the <strong>Partner</strong> Organization must address the request directly to the responsible <strong>PPN</strong><br />

Manager.<br />

4.9. The <strong>Partner</strong> Organization must undertake suitable measures to prevent unauthorized<br />

persons from taking over control <strong>of</strong> a PC or Notebook that is logged in to <strong>PPN</strong> or from<br />

tracking <strong>Use</strong>r actions. This comprises physical access as well as remote access, especially<br />

from the Internet. The relevant IT security guidelines to comply with are described in a<br />

separate document.<br />

4.10. <strong>PPN</strong> Certificates issued by <strong>Porsche</strong> in any <strong>for</strong>m and via any media may not be copied or<br />

handed to persons who are not authorized by <strong>Porsche</strong> to use <strong>PPN</strong>.<br />

4.11. <strong>PPN</strong> Certificates stored on PCs or Notebooks no longer used by authorized persons <strong>for</strong><br />

accessing <strong>PPN</strong> must be removed irrecoverably from these devices. This applies particularly<br />

to any devices that will be sold or no longer be under constant physical control <strong>of</strong> the<br />

<strong>Partner</strong> Organization.<br />

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 4 <strong>of</strong> 6<br />

Version 2.4


5. Exclusion <strong>of</strong> Warranty and Liability<br />

<strong>Porsche</strong> has employed state <strong>of</strong> the art Internet security and encryption technology in order to<br />

ensure the highest level <strong>of</strong> security possible. However, no network or system can be made 100 %<br />

secure. There<strong>for</strong>e, any warranty or liability <strong>of</strong> <strong>Porsche</strong> or any other claims in connection therewith<br />

against <strong>Porsche</strong> <strong>for</strong> any reason whatsoever are excluded. <strong>Porsche</strong> shall not be liable <strong>for</strong> any loss<br />

or damage that results from the use, per<strong>for</strong>mance or availability <strong>of</strong> the <strong>PPN</strong> infrastructure.<br />

Furthermore, as the public Internet is used as communication plat<strong>for</strong>m, <strong>Porsche</strong> has no control <strong>of</strong><br />

the communication path, and there<strong>for</strong>e, is not able to guarantee a certain quality <strong>of</strong> service.<br />

<strong>Porsche</strong> is also not liable <strong>for</strong> any damages that result from lost or manipulated data transmitted<br />

over the <strong>PPN</strong> infrastructure.<br />

No warranties, whether express or implied, including but not limited to the implied warranties <strong>of</strong><br />

merchantability or fitness <strong>for</strong> a particular purpose, are made. In no event will <strong>Porsche</strong> be liable to<br />

<strong>Partner</strong> Organizations or any other party <strong>for</strong> any incidental or consequential damages that may<br />

arise from use <strong>of</strong> the <strong>PPN</strong>.<br />

6. Other Conditions<br />

6.1. The fact that <strong>Porsche</strong> provides the <strong>PPN</strong> infrastructure does not support any claim <strong>of</strong> a<br />

<strong>Partner</strong> Organization to be given access to it.<br />

6.2. <strong>Porsche</strong> may end the <strong>PPN</strong> infrastructure service without prior notice because <strong>of</strong> business<br />

reasons or <strong>for</strong>ce majeure. If possible, <strong>Porsche</strong> will advise the <strong>Partner</strong> Organization within an<br />

adequate period <strong>of</strong> time prior to the discontinuation.<br />

6.3. Changes and supplements to this Document can only be made in writing and will be<br />

released in a new version replacing all older ones.<br />

6.4. New versions <strong>of</strong> these terms become effective when made available through the <strong>PPN</strong> online<br />

interface. There is no need <strong>for</strong> a separate notification. The existence <strong>of</strong> a newer version<br />

automatically leads to a replacement <strong>of</strong> all older versions.<br />

6.5. A <strong>Partner</strong> Organization may terminate the usage <strong>of</strong> <strong>PPN</strong> at any time with five working days<br />

notice by written letter or fax to the <strong>PPN</strong> Manager so that all <strong>of</strong> its <strong>Use</strong>r accounts can be<br />

disabled. The liability to keep all <strong>PPN</strong> related in<strong>for</strong>mation confidential continues also after<br />

the termination <strong>of</strong> the usage <strong>for</strong> a period <strong>of</strong> three (3) years.<br />

6.6. In the event a <strong>Partner</strong> Organization violates one or more regulations <strong>of</strong> these terms and<br />

conditions <strong>for</strong> <strong>PPN</strong>, <strong>Porsche</strong> may, in its sole discretion and without prejudice to any other<br />

rights it may have, deactivate all <strong>Use</strong>r accounts <strong>of</strong> the <strong>Partner</strong> Organization immediately<br />

without prior notice.<br />

6.7. Should a provision in this agreement be found to be invalid, the validity <strong>of</strong> the remaining<br />

provisions in the agreement shall remain unaffected. The invalid provision shall be replaced<br />

by a provision, which, in a legally acceptable manner, comes closest to realizing the<br />

economic purpose intended by the invalid provision.<br />

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 5 <strong>of</strong> 6<br />

Version 2.4


6.8. These <strong>Terms</strong> <strong>of</strong> use are governed by the laws <strong>of</strong> the Federal Republic <strong>of</strong> Germany without<br />

regard to conflict <strong>of</strong> laws rules. The place <strong>of</strong> fulfilment <strong>for</strong> all obligations arising from these<br />

terms <strong>of</strong> use and the sole place <strong>of</strong> jurisdiction is Stuttgart, Germany.<br />

<strong>Terms</strong> <strong>of</strong> <strong>Use</strong> <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 6 <strong>of</strong> 6<br />

Version 2.4


IT Security Guidelines<br />

<strong>for</strong><br />

<strong>Porsche</strong> <strong>Partner</strong> <strong>Network</strong> (<strong>PPN</strong>)<br />

Version 1.1 Date: 26 Jan. 06<br />

This version replaces all prior versions <strong>of</strong> this document.<br />

Dr. Ing. h.c. F. <strong>Porsche</strong> Aktiengesellschaft<br />

(hereinafter “<strong>Porsche</strong>”)<br />

<strong>Porsche</strong>strasse 15 – 19<br />

71634 Ludwigsburg<br />

Germany<br />

Page 1 <strong>of</strong> 3


Preamble<br />

It is <strong>of</strong> great interest <strong>for</strong> <strong>Porsche</strong> that <strong>PPN</strong> <strong>Use</strong>rs work in a secure IT environment. Our<br />

common business should not be affected by computer viruses, unauthorized access to<br />

systems, manipulation <strong>of</strong> data by third parties or instability <strong>of</strong> data communication.<br />

For this reason, <strong>Porsche</strong> has established these IT security guidelines to enable the<br />

<strong>Porsche</strong> <strong>Partner</strong>s keeping a high level <strong>of</strong> IT security in their day-to-day work.<br />

In case there are any uncertainties regarding IT security, the <strong>Partner</strong> IT administrator<br />

should be able to help the user. Please contact the responsible <strong>PPN</strong> Manager <strong>for</strong> further<br />

in<strong>for</strong>mation.<br />

1. Anti Virus S<strong>of</strong>tware<br />

IT security rules in brief:<br />

<strong>Use</strong>rs may not<br />

• share their <strong>PPN</strong> account,<br />

• save or store their password on the PC,<br />

• use a <strong>PPN</strong> Certificate on a private or public PC or<br />

• leave their PC unlocked when away.<br />

The <strong>Partner</strong> Organisation has to ensure that<br />

• PCs are protected from viruses,<br />

• a firewall protects the PC or network from external<br />

access and<br />

• physical access to PCs is limited to <strong>Partner</strong> personnel.<br />

The PCs used <strong>for</strong> <strong>PPN</strong> access must have an Anti Virus S<strong>of</strong>tware installed with actual virus<br />

definitions. Otherwise it is possible that data may be deleted or manipulated. It is also<br />

possible that the user spreads a virus to other people’s computers. A virus may also allow<br />

other people to track the user’s action or to use their computer to take unwanted action.<br />

2. Connection to the Internet<br />

The connection to the Internet must be protected by an up to date firewall. This can either<br />

be a special device or a piece <strong>of</strong> s<strong>of</strong>tware installed on the users computer.<br />

IT Security Guidelines <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 2 <strong>of</strong> 3<br />

Version 1.1


3. <strong>Use</strong>rnames and Passwords<br />

The most vital part to prevent unauthorized use <strong>of</strong> <strong>Porsche</strong> in<strong>for</strong>mation systems is the<br />

personal identification <strong>of</strong> the user. If somebody else gets to know the username and<br />

password <strong>of</strong> the user or gets a copy <strong>of</strong> the user’s certificate, they may undertake<br />

unwanted actions using these credentials. To prevent this, the user may not store their<br />

username and password <strong>for</strong> <strong>PPN</strong> and other systems at publicly accessible places or in<br />

databases. <strong>Use</strong>rs must not use the “remember password” function <strong>of</strong> their<br />

browser. If written down, username and password must not be stored in the<br />

same place and never at the user’s PC or display.<br />

4. Configuration <strong>of</strong> the IT security components<br />

Every component (Anti Virus S<strong>of</strong>tware, Firewall, etc.) that protects the user from IT<br />

security risks is only as good as its configuration. In case there are doubts about one or<br />

several settings <strong>of</strong> the components, involve your responsible IT administrator.<br />

5. Sharing <strong>of</strong> user accounts<br />

To access <strong>PPN</strong> via Internet every user must have a personal user account. Joint usage <strong>of</strong><br />

one account by two or more people is strictly prohibited. This is not only an IT security<br />

measure <strong>for</strong> <strong>Porsche</strong> but also <strong>for</strong> the user as nobody else should be able to undertake<br />

actions with their user credentials.<br />

6. Access to the users computer<br />

If <strong>Use</strong>rs leave their desk, they must always disconnect from <strong>PPN</strong> or block their computer<br />

as other people may use their <strong>PPN</strong> connection while they are away.<br />

7. Sharing <strong>of</strong> a Computer<br />

If <strong>Use</strong>rs share a computer with colleagues, all <strong>of</strong> them need to use their own user account<br />

to access <strong>PPN</strong> via Internet. This requires a separate user request and setup <strong>for</strong> each<br />

person.<br />

8. <strong>PPN</strong> Certificates<br />

<strong>PPN</strong> certificates may only be used on workplaces <strong>of</strong> the <strong>Partner</strong> Organisations but not on<br />

private or public PCs.<br />

IT Security Guidelines <strong>for</strong> <strong>PPN</strong> Date: 26 Jan. 06 Page 3 <strong>of</strong> 3<br />

Version 1.1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!