Data Processing Addendum
Last updated 2026-09-24
1. Scope and how this Addendum applies
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Cheetah Technologies LLC ("Cheetah", "we", "us") and the business that subscribes to Cheetah OS ("Customer", "you"). It applies whenever Cheetah processes Customer Personal Data in providing the Service. It takes effect when the Customer accepts the Agreement and lasts as long as Cheetah processes Customer Personal Data.
If this DPA conflicts with the Agreement, this DPA controls on data protection matters. If a transfer mechanism incorporated under Section 13 conflicts with this DPA, the transfer mechanism controls.
2. Definitions
- Applicable Data Protection Law means all privacy, data protection and data security laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations ("CCPA"), the other US state comprehensive privacy laws, the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314) to the extent they apply to the Customer, the UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and, where applicable, the EU General Data Protection Regulation ("EU GDPR").
- Customer Personal Data means personal information or personal data in Customer Data that Cheetah processes on the Customer's behalf.
- Customer Data means the data the Customer and its Users submit to or generate in the Service.
- Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Cheetah or its Sub-processors.
- Sub-processor means a third party Cheetah engages that processes Customer Personal Data.
- controller, processor, business, service provider, data subject, consumer, personal data, processing, sell, share and similar terms have the meanings given in Applicable Data Protection Law.
3. Roles of the parties
For Customer Personal Data, the Customer is the controller (or "business") and Cheetah is the processor (or "service provider"). Where the Customer is itself a processor for another controller, Cheetah is the Customer's sub-processor, and the Customer confirms that its instructions are authorized by that controller.
Cheetah is a controller only for its own account, billing, security and Site data, as described in the Privacy Policy. That data is not governed by this DPA.
4. Details of the processing
The subject matter, nature, purpose, duration, types of personal data and categories of data subjects are set out in Exhibit A.
5. Customer responsibilities
The Customer:
- is responsible for the lawfulness of the Customer Personal Data it provides and the instructions it gives, and has a lawful basis for the processing;
- gives the notices and obtains the consents Applicable Data Protection Law and other laws require, including privacy notices to merchants, guarantors, leads and investors; notices and consent for call recording, including in states that require the consent of all parties; prior express consent or prior express written consent for calls and texts under the Telephone Consumer Protection Act and state laws; and, if and when biometric features are enabled, written notice and written consent before any biometric identifier is collected;
- does not upload protected health information, information about children, or data it has no right to use;
- configures the Service, including User access, multi-factor authentication for its Users, and retention settings, appropriately for its data; and
- is responsible for its own decisions about individuals, including credit and funding decisions, adverse action notices and any obligations that apply to it as a deployer of automated decision technology.
6. Cheetah's obligations
Processing on instructions
Cheetah will process Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA, and the Customer's use and configuration of the Service are the Customer's complete instructions at the time of signature. Additional instructions must be agreed in writing. Cheetah will tell the Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing until the instruction is confirmed or changed. If the law requires Cheetah to process Customer Personal Data other than on instructions, Cheetah will tell the Customer before processing unless the law prohibits it.
Business purposes
Cheetah processes Customer Personal Data only for the following business purposes: providing, maintaining, securing and supporting the Service for the Customer; preventing and investigating security incidents, fraud and abuse affecting the Service; fixing errors; and complying with law.
Confidentiality
Cheetah will ensure that everyone it authorizes to process Customer Personal Data is bound by a duty of confidentiality, whether contractual or statutory, and has access only as needed to perform the Service.
Limits on use
Cheetah will not:
- sell or share Customer Personal Data;
- retain, use or disclose Customer Personal Data for any purpose other than the business purposes above, including any commercial purpose, or outside the direct business relationship with the Customer;
- combine Customer Personal Data with personal information it receives from or on behalf of another person, or collects from its own interactions with individuals, except as Applicable Data Protection Law permits;
- use Customer Personal Data, including call recordings, transcripts and message content, to train or improve artificial intelligence models, or allow its Sub-processors to do so; or
- use Customer Personal Data for its own marketing or to build or improve services for other customers.
7. Security
Cheetah will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, costs, the nature, scope, context and purposes of processing, and the risks to individuals. The measures in place today are described in Exhibit B. Cheetah may update them, but will not materially reduce the overall level of protection during the term of the Agreement.
8. Sub-processors
Authorization
The Customer gives Cheetah general authorization to engage Sub-processors. The current list, with purpose, data involved and location, is published at Sub-processors.
Notice and objection
Cheetah will give the Customer at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, by [[FILL: notice method, e.g. email to Customer administrators and an update to the Sub-processors page]]. The Customer may object on reasonable data protection grounds by writing to privacy@cheetahos.app within that 30-day period. The parties will discuss the objection in good faith. If Cheetah cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service by written notice and receive a refund of prepaid fees for the unused period [[FILL: confirm commercial remedy]]. In an emergency, such as replacing a Sub-processor that has failed or become insecure, Cheetah may give notice as soon as possible after the change.
Flow-down and liability
Cheetah will enter into a written agreement with each Sub-processor that imposes data protection obligations at least as protective as this DPA, to the extent applicable to the services the Sub-processor provides. Cheetah remains responsible for its Sub-processors' performance of those obligations.
9. Assistance
Data subject requests
Taking into account the nature of the processing, Cheetah will assist the Customer by appropriate technical and organizational measures to respond to requests from individuals to exercise their rights. The Service lets the Customer find and correct Customer Personal Data in its records and lets an administrator export the Customer's account data. Where the Service does not provide a self-service way to delete particular data, such as documents, recordings or messages, Cheetah will delete it on the Customer's request. If Cheetah receives a request directly from an individual that relates to Customer Personal Data, it will forward the request to the Customer within [[FILL: e.g. 10 business days]] and will not respond to the individual except to tell them it has passed the request on, unless the Customer instructs otherwise. Cheetah will also promptly forward to the Customer any data protection complaint it receives about Customer Personal Data.
Assessments and regulators
Cheetah will provide reasonable information and assistance the Customer needs to carry out data protection impact assessments, risk assessments (including those required by California regulations), and prior consultations with regulators, to the extent the Customer does not otherwise have access to that information. Where the Customer uses Service features that could be considered automated decision technology under Colorado law or California regulations, Cheetah will provide available documentation describing those features, their intended uses, known limitations and how human review works. Cheetah will cooperate with reasonable requests from regulators with authority over the Customer.
10. Personal Data Breaches
Cheetah will notify the Customer of a Personal Data Breach without undue delay, and in any case within 72 hours after Cheetah confirms it [[FILL: counsel may shorten]]. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Cheetah will provide further information as it becomes available, take reasonable steps to contain and remediate the breach, and cooperate with the Customer's investigation and its notifications to regulators and individuals, including notices under state breach laws, the FTC Safeguards Rule (16 CFR 314.4(j)) and SEC Regulation S-P where they apply to the Customer.
Cheetah will not notify the Customer's data subjects or regulators about a Personal Data Breach on the Customer's behalf, or name the Customer publicly in connection with it, without the Customer's approval, unless the law requires it. Notice of a breach is not an admission of fault.
11. Audits and information
Cheetah will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. Cheetah will first meet audit requests by answering a reasonable written security questionnaire once per year and providing relevant security documentation, and by providing any independent audit report it holds at the time. Cheetah does not currently hold a SOC 2 report or ISO 27001 certification.
If that information is not enough to demonstrate compliance, or a regulator requires it, the Customer may, at its own cost and once in any 12-month period, carry out an audit using an independent auditor bound by confidentiality, on at least 30 days' written notice, during business hours, in a way that does not disrupt the Service or expose other customers' data. The Customer will share the audit results with Cheetah. Cheetah may take reasonable steps to stop and remediate any unauthorized use of Customer Personal Data that the Customer identifies.
12. Return and deletion
During the subscription, the Customer can export Customer Data using the Service. After the Agreement ends, the Customer has 30 days [[FILL: confirm]] to export its data. After that period, Cheetah will delete Customer Personal Data and destroy the Customer's tenant encryption keys, which makes any remaining encrypted copies unreadable. Encrypted backups expire on Cheetah's backup schedule [[FILL: backup retention period]]. Cheetah may keep Customer Personal Data where the law requires it, in which case this DPA continues to protect it and Cheetah will process it only for that purpose. On request, Cheetah will confirm deletion in writing.
13. International transfers
Cheetah and its Sub-processors process Customer Personal Data in the United States [[FILL: confirm regions]]. Cheetah will not transfer Customer Personal Data to another country except in compliance with Applicable Data Protection Law.
- UK. Where the Customer transfers Customer Personal Data subject to the UK GDPR to Cheetah in the United States, the parties rely on [[FILL: the UK Extension to the EU-US Data Privacy Framework if Cheetah self-certifies, and otherwise]] the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, which are incorporated by reference with the Customer as exporter and Cheetah as importer [[FILL: counsel to complete the tables and choose the mechanism]]. Cheetah will provide the information the Customer reasonably needs for its transfer risk assessment under the "not materially lower" data protection test.
- EU. Where EU GDPR applies, the EU Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable) are incorporated by reference [[FILL: counsel to complete options and annexes]].
- Onward transfers. Cheetah is responsible for ensuring an appropriate transfer mechanism is in place for transfers to its Sub-processors.
14. US state law terms
California
Cheetah is a service provider under the CCPA. In addition to Section 6, Cheetah will comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses, and will notify the Customer if it determines it can no longer meet its obligations. The Customer may take reasonable and appropriate steps to ensure that Cheetah uses Customer Personal Data consistently with the Customer's CCPA obligations and, on notice, to stop and remediate unauthorized use. Cheetah will cooperate with the Customer in responding to verifiable consumer requests. Cheetah certifies that it understands the restrictions in this DPA and will comply with them.
Virginia model states
For Customer Personal Data governed by the laws of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Minnesota and other states with similar processor requirements, Cheetah will: process only on documented instructions; ensure a duty of confidentiality; engage Sub-processors only under written contracts that require them to meet Cheetah's obligations, after giving the Customer an opportunity to object; delete or return Customer Personal Data at the end of the services unless retention is required by law; make available all information in its possession necessary to demonstrate compliance; allow and cooperate with reasonable assessments as described in Section 11; and assist the Customer with data protection assessments, security, breach notification and individuals' requests. Where Oregon or Minnesota law applies, Cheetah will help the Customer respond to requests for a list of specific third parties and maintain its data inventory. Where Texas law applies, Cheetah will provide the information the Customer needs about any AI features the Customer uses.
15. Financial institution customers (GLBA)
Where the Customer is a financial institution under the Gramm-Leach-Bliley Act and Customer Personal Data includes customer information or nonpublic personal information:
- Cheetah will implement and maintain the safeguards in Exhibit B, which are designed to protect the security and confidentiality of that information, protect against anticipated threats or hazards, and protect against unauthorized access or use;
- Cheetah will not disclose or use that information other than to carry out the services under the Agreement, consistent with 12 CFR 1016.11 and 1016.13;
- Cheetah will notify the Customer of a Personal Data Breach as described in Section 10 so the Customer can meet its own notification duties, including notice to the FTC within 30 days where 16 CFR 314.4(j) applies and service provider notice within 72 hours under SEC Regulation S-P where it applies; and
- Cheetah will cooperate with the Customer's periodic assessment of Cheetah as a service provider through the process in Section 11.
16. UK and EU processor terms
Where the UK GDPR or EU GDPR applies, this DPA is intended to meet Article 28(3). In particular, Sections 6 (instructions and confidentiality), 7 and Exhibit B (security under Article 32), 8 (sub-processors), 9 (assistance with data subject rights and with Articles 32 to 36), 10 (breach notification under Article 33(2)), 11 (audits and information) and 12 (deletion or return) apply. Cheetah will keep records of processing as required by Article 30(2), will cooperate with the supervisory authority, and has appointed a UK representative under Article 27: [[FILL: UK representative]]. Cheetah will promptly forward to the Customer any data protection complaint it receives so the Customer can meet its complaints handling duty under section 164A of the Data Protection Act 2018.
17. Communications, recordings and AI
Call recordings, transcripts, text messages, emails and AI assistant inputs and outputs that contain Customer Personal Data are processed only to provide the Service to the Customer. Cheetah does not listen to, read or use them for its own purposes, except where needed to provide support the Customer asks for, to investigate security incidents or abuse, or to comply with law. Cheetah requires its AI Sub-processors not to use Customer Personal Data to train their models [[FILL: confirm provider terms, including zero retention]].
18. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement [[FILL: counsel to decide whether a separate cap applies to data protection breaches]]. Nothing in this DPA limits either party's liability to individuals or regulators where the law does not allow it to be limited.
19. Changes
Cheetah may update this DPA to reflect changes in Applicable Data Protection Law or the Service by giving at least 30 days' notice, provided the update does not materially reduce the protection of Customer Personal Data. If a change is required by law, it may take effect sooner.
Exhibit A: Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing the Cheetah OS Service to the Customer |
| Duration | The term of the Agreement plus the export and deletion period in Section 12 |
| Nature of processing | Hosting, storage, encryption, retrieval, organization, display, transmission of calls, text messages and email, call recording, document storage and malware scanning, search, export, AI-assisted drafting and summarization at a User's request, backup and deletion |
| Purpose | The business purposes in Section 6 |
| Categories of data subjects | Merchants and business owners; personal guarantors; leads and prospects of the Customer; call and message recipients; investors and syndicators; the Customer's staff and Users; other individuals named in documents the Customer uploads |
| Types of personal data | Names and contact details; business identifiers; Social Security numbers and other national identifiers; dates of birth; home addresses; identity documents; bank statements and account details; tax forms (including Forms W-9 and W-4); credit-related information; financing, deal, participation and distribution records; call recordings and call metadata; text message and email content; notes and uploaded documents; User account and audit data |
| Sensitive data | Government identifiers, identity documents, financial account information and, if and when biometric identity verification is enabled, biometric identifiers. No special category data is intended; Customers must not upload health information |
| Frequency | Continuous during the term |
Exhibit B: Security measures
The measures in place today are:
- Tenant isolation. Each Customer's data is logically separated, and every access is checked against the requesting User's organization and role.
- Per-tenant encryption keys for sensitive Customer Data, destroyed at the end of the deletion period in Section 12.
- Field-level encryption of sensitive fields, such as national identifiers, in addition to storage encryption.
- Encrypted document storage in Amazon Web Services S3 with keys managed through AWS Key Management Service.
- Encryption in transit using TLS.
- Tamper-evident, hash-chained audit log of significant actions.
- Authentication. Passkeys and time-based one-time password multi-factor authentication; MFA is mandatory for Cheetah's internal staff roles and available to all Customer Users; breached-password screening.
- Malware scanning of uploaded files.
- Least-privilege access for Cheetah staff and systems.
- Bot protection through Cloudflare Turnstile.
- Error monitoring through Sentry.
Organizational measures [[FILL: confirm each before signature: named person responsible for the security program; written information security program; risk assessment cadence; incident response plan; vulnerability management and patching; backup and restore testing; staff confidentiality agreements and security training; penetration testing; change management]].
Exhibit C: Sub-processors
See Sub-processors.
Contact
Data protection questions about this DPA: privacy@cheetahos.app [[FILL: confirm mailbox exists]]. General enquiries: info@cheetahos.app. Cheetah Technologies LLC, [[FILL: mailing address]].
