factual

What is the consequence of a Compromised Data Event or Data Security Event for Even Hotels?

Even_Hotels Franchise · 2025 FDD

Answer from 2025 FDD Document

  • 4.4 Your Compromised Data Event. If a Compromised Data Event (as defined in Section 4.8) occurs or is suspected to have occurred, you must, at your own expense: (a) perform or cause to be performed an independent investigation, including a forensics analysis performed by a certified forensic vendor acceptable to us and the Card Organizations in accordance with Card Organization standards, of any data security breach of Cardholder data or Transaction Data; (b) provide a copy of the certified forensic vendor's final report regarding the incident to us and the Card Organizations; (c) perform or cause to be performed any remedial actions recommended by any such investigation; and (d) cooperate with us in the investigation and resolution of any security breach. Notwithstanding the foregoing, if required by a Card Organization, we will engage a forensic vendor approved by a Card Organization at your expense. You must cooperate with the forensic vendor so that it may immediately conduct an examination of your equipment and other Merchant Systems, and your and Merchant Providers' procedures and records, and so that it may issue a written report of its findings.
  • 4.5 Our Data Security Event. If we are determined by a Card Organization to have breached our data security obligations under Applicable Law or the Card Organization Rules, resulting solely from our independent acts or omissions which results in the actual, unauthorized disclosure of personally identifiable consumer information, including but not limited to Cardholder data that is submitted to us by you hereunder, (a “Data Security Event”), we will be responsible for performing each of the actions set forth in subparts (a) and (c) of Section 4.4.

Source: Item 23 — RECEIPTS (FDD pages 99–438)

What This Means (2025 FDD)

According to Even Hotels' 2025 Franchise Disclosure Document, if a Compromised Data Event occurs or is suspected to have occurred, the franchisee is responsible for several actions at their own expense. These include performing an independent investigation, which must incorporate a forensics analysis by a certified vendor acceptable to both Even Hotels and the Card Organizations. The franchisee must then provide copies of the vendor's final report to Even Hotels and the Card Organizations.

Furthermore, the franchisee must undertake any remedial actions recommended by the investigation and cooperate with Even Hotels in investigating and resolving any security breach. However, if a Card Organization requires it, Even Hotels will engage a forensic vendor approved by the Card Organization, but the franchisee will still bear the expense. In such cases, the franchisee must cooperate fully with the forensic vendor, allowing them to examine equipment, systems, procedures, and records, and to issue a written report of their findings.

In contrast, if Even Hotels is determined by a Card Organization to have breached its data security obligations due to its independent acts or omissions, resulting in the unauthorized disclosure of personally identifiable consumer information, including cardholder data submitted by the franchisee, Even Hotels will be responsible for performing the actions outlined in subparts (a) and (c) of Section 4.4. These actions include performing an independent investigation and undertaking any necessary remedial actions.

Disclaimer: This information is extracted from the 2025 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.