All legal documents

Privacy Policy

Last updated 2026-09-24

1. Who we are and what this policy covers

Cheetah OS is business software made by Cheetah Technologies LLC, a limited liability company organized in the State of Arizona, United States, and based in Phoenix, Arizona ("Cheetah", "we", "us"). Our mailing address is [[FILL: mailing address]].

Cheetah OS is used only by businesses: loan and financing brokers and independent sales organizations (ISOs), business funders (including merchant cash advance providers), underwriters, syndicators and investors, and their staff. It is not offered to consumers and is not intended for anyone under 18. We do not lend, broker, fund, collect debts, or make credit or funding decisions. Our customers do those things, using our software.

This policy covers:

  • our website at cheetahos.app (the "Site"), including its contact form, instant demo request, and "Ask our AI" chat;
  • the Cheetah OS application at app.cheetahos.app (the "Service"); and
  • the personal information our customers store in the Service about other people, such as merchants, business owners and personal guarantors.

Related documents: Terms of Service, Data Processing Addendum, Sub-processors, Cookie Notice, AI Disclosures, Communications Policy and Accessibility Statement.

2. Our two roles

We handle personal information in two different roles, and the rules differ for each.

We are the controller (the "business" under US state law) for our own information. This covers people who visit the Site, prospects and people who submit our contact or demo forms, people who sign in to the Service ("Users"), billing contacts, and our own staff and contractors. We decide how and why this information is used, and this policy describes our practices.

We are a processor (a "service provider" or "processor" under US state law) for Customer Data. Customer Data is the information our customers put into the Service about other people, for example merchants and business owners, personal guarantors, leads, call recipients, investors, and the customer's own staff. The customer that collected the information is the controller. It decides what to collect and why, and we process that information only to provide the Service to that customer, under its instructions and our Data Processing Addendum. If your information is in the Service because of your dealings with one of our customers, please read Section 21.

3. Information we collect as a controller

Site visitors

  • Technical data. When you visit the Site, our hosting provider receives the technical information your browser sends, such as your IP address, browser type, the pages you request and the time of the request, so the Site can be delivered and protected.
  • Rate limiting. To stop abuse of our forms and chat, we store a salted hash of your IP address (not the IP address itself) in our database for a limited time.
  • Bot protection. Our instant demo request uses a hidden form field that people never fill in, together with the rate limiting above, to block automated bots. The Site does not use a third-party bot protection service.
  • No tracking. The Site does not use analytics tools, advertising pixels, retargeting tags or session replay. We do not track you across other websites.

Contacting us and instant demo requests

  • Contacting us. The Site does not have a contact form. If you email us, we receive the details you choose to include, such as your name, email address, company and message.
  • Instant demo. The demo request asks only which product tier you want to try; it does not ask for your name or contact details. A demo request creates a temporary demo account in the Service. The demo account is loaded with synthetic (made up) business data, not real people's information.

Ask our AI (Site chat)

The Site offers an AI product chat labeled "Ask our AI". It is an automated AI assistant, not a person. When you use it, the messages you type are sent to Groq, a third-party AI inference provider, to generate replies. Please do not enter sensitive information such as Social Security numbers, bank details or health information into the chat. We do not store chat transcripts; we keep only the salted hash of your IP address used for rate limiting. Groq processes your messages under its own terms.. See our AI Disclosures.

Users of the Service

  • Account details: name, work email, phone number, role, organization, and your password, which we store only as a salted hash.
  • Sign-in security data: passkey public keys and an encrypted time-based one-time password (TOTP) secret if you set up multi-factor authentication.
  • Session and security data: sign-in times, IP address, device and browser information, and security events.
  • Activity records: the actions you take in the Service. Significant actions are recorded in a tamper-evident audit log attributed to the User who performed them.
  • Connected mailboxes (optional): if you connect your own Google or Microsoft mailbox for email outreach, we store the credentials or authorization token needed to send and read mail on your behalf, encrypted.
  • Support communications: messages you send us and our replies.

Billing contacts

Subscription payments are handled by Stripe. Stripe collects card and bank details directly. We receive a customer identifier, the card brand and last four digits, billing name and address, and invoice and payment status. We never store full card numbers.

Our staff and contractors

When we engage staff or contractors, we collect the information needed to engage, pay and manage them, such as contact details, tax forms (for example Form W-9 or W-4), identity documents, and payment details [[FILL: confirm]]. We give staff and contractors a separate notice at the time of collection.

Sources

We collect this information directly from you, automatically from your browser or device, from the customer organization that invites you as a User, from Stripe for billing status, and from Cloudflare Turnstile for bot signals. We do not buy personal information from data brokers or lead sellers.

4. Information we process for our customers (Customer Data)

Depending on how a customer uses Cheetah OS, Customer Data can include:

  • Merchants and business owners: names, business names, contact details, business identifiers, applications, financing history and deal records.
  • Personal guarantors and owners: names, contact details, Social Security numbers or other national identifiers, date of birth, home address, identity documents, bank statements, tax forms, and credit-related information.
  • Leads and contacts: names, phone numbers, email addresses, notes and consent status for calls and texts.
  • Communications: call logs and call recordings, text message content, email content, and related metadata.
  • Investors and syndicators: names, contact details, participation and distribution records.
  • Customer staff onboarding records: tax forms (for example Form W-9 and W-4) and identity documents.
  • Documents and notes that the customer uploads or writes.

We process Customer Data only to provide, secure and support the Service for the customer that owns it, as described in our Data Processing Addendum. We do not sell Customer Data, we do not use it for our own marketing, we do not use it to train AI models, and we do not combine one customer's data with another customer's data. Each customer's data is kept separate from every other customer's data and is encrypted with that customer's own keys.

Cheetah OS is not designed to store health information. Customers agree not to upload protected health information.

5. How we use personal information

We use the information in Section 3 to:

  1. provide, operate and maintain the Site and the Service, including demo accounts;
  2. create and manage accounts, authenticate Users, and enforce roles and permissions;
  3. answer questions you send through our forms or the Site chat;
  4. bill subscriptions and manage payments through Stripe;
  5. send service messages, such as sign-in verification, security alerts, receipts and important account notices;
  6. send marketing about Cheetah OS where the law allows, with an opt-out in every message;
  7. keep the Site and the Service secure, detect and prevent fraud, abuse and unauthorized access, and keep audit records;
  8. find and fix errors and performance problems;
  9. comply with law, respond to lawful requests, and establish or defend legal claims; and
  10. manage our relationship with our staff and contractors.

We use Customer Data only for the purposes set out in Section 4 and in our Data Processing Addendum.

If UK or EU data protection law applies to our processing as a controller, we rely on these legal bases:

PurposeLegal basis
Providing the Service and managing accounts and subscriptionsPerformance of our contract with the customer, and our legitimate interest in serving the customer's authorized Users
Responding to contact form, demo and chat requestsLegitimate interests in responding to business enquiries, or steps taken at your request before entering a contract
Billing, accounting and tax recordsLegal obligation, and performance of contract
Security, fraud prevention, bot protection, rate limiting and audit logsLegitimate interests in network and information security
Error monitoring and service improvementLegitimate interests in running a reliable service
Business-to-business marketingLegitimate interests in promoting our services, or consent where the law requires it (for example for some sole traders and partnerships)
Legal compliance and legal claimsLegal obligation, and legitimate interests in protecting our rights
Staff and contractor administrationPerformance of contract and legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights. You can ask us for more information about that balancing. Where we rely on consent, you can withdraw it at any time.

7. How we disclose personal information

We disclose personal information only as follows:

  • Sub-processors and service providers that help us run the Site and the Service, under written contracts that limit their use of the information to providing services to us. The full list, with purposes, data involved and locations, is on our Sub-processors page. It includes Neon (database), Vercel (hosting), Amazon Web Services S3 with KMS (document storage), Stripe (billing), Telnyx (voice, text messages, phone numbers and call recording), Resend (transactional email), Sentry (error monitoring), Cloudflare (Turnstile bot protection), Groq (Site chat), a malware scanning provider, a phone number reputation provider, and a large language model provider for the in-app assistant.
  • Services you or your organization connect. If a customer connects its own Google or Microsoft mailbox, messages are sent and read through that provider at the customer's direction.
  • Your organization. If you are a User, your organization's administrators can see your account details and activity in the Service.
  • Legal and safety reasons. To comply with law, a court order, subpoena or other lawful request; to enforce our terms; and to protect the rights, property or safety of our customers, others or us. Where the law allows, we will tell the affected customer before disclosing its Customer Data.
  • Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that deal, subject to this policy, with notice to affected customers.
  • With your direction or consent.

8. We do not sell or share personal information

We do not sell personal information, and we have not sold it in the past 12 months. We do not share personal information for cross-context behavioral advertising or targeted advertising, and we have not done so in the past 12 months. The Site has no advertising pixels or trackers. We do not knowingly sell or share the personal information of anyone under 16.

Because we do not sell or share personal information, we do not display a "Do Not Sell or Share My Personal Information" link. If that ever changes, we will update this policy, add the required links and choices first, and honor opt-out preference signals.

9. Sensitive personal information

As a controller, the sensitive personal information we handle is limited to account sign-in credentials for Users and, for our own staff and contractors, government identifiers, identity documents and payment details. We use and disclose that information only for purposes the law allows without offering a right to limit, such as providing the Service, security and integrity, and legal compliance. We do not use it to infer characteristics about anyone.

Customer Data often includes sensitive information, such as Social Security numbers, identity documents, bank statements and tax forms. We process it only as a processor, to provide the Service to the customer that owns it. The customer decides whether it has the right to collect that information.

10. AI processing

  • Site chat. "Ask our AI" is labeled as AI. Your chat messages are sent to Groq to generate replies. Replies can be wrong. It is not legal, tax, credit or financial advice.
  • In-app assistant. Cheetah OS includes an AI assistant. When a User asks it for help, the request and the information in the Service needed to answer it are sent to a large language model provider [[FILL: large language model provider]]. The assistant sends the request and recent conversation, the User's first name, role and organization name, and the records it looks up to answer (for example a lead's merchant name, status and masked phone number).
  • No training on Customer Data. We do not use Customer Data to train AI models, and our AI providers are not permitted to use it to train their models [[FILL: confirm provider zero-retention and no-training terms]]. We will not start using personal information to train AI models without first updating this policy and, for Customer Data, obtaining the customer's affirmative agreement.
  • Human decisions. Our AI features assist people. They do not make credit, funding, approval, pricing or employment decisions.

More detail is in our AI Disclosures.

11. Calls, recordings and text messages

Customers can use Cheetah OS to place and receive calls, record calls, and send text messages and email through Telnyx and Resend. The content and records of those communications are Customer Data. The customer is the caller or sender and is responsible for giving any notice and obtaining any consent the law requires before calling, texting, emailing or recording someone, including in states that require the consent of everyone on a call. We process recordings, transcripts and messages only to provide the Service to that customer, never for our own purposes and never to train AI models.

Text messaging. Mobile phone numbers and text message opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. We share mobile numbers only with the service providers that deliver the messages (such as Telnyx and the mobile carriers) as needed to send them. This applies both to messages we send and to messages our customers send through Cheetah OS. Replies such as STOP, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE and OPT OUT are recorded as opt-outs. See our Communications Policy for message frequency, rates and HELP instructions.

12. Features that may be enabled later

The features below are not live today. If and when we enable them, this section describes how they will work, and we will update this policy and our Sub-processors page before launch.

  • Document integrity and fraud signals. If and when enabled, Cheetah OS may analyze documents a customer uploads (for example bank statements) and flag possible alterations or inconsistencies. Signals will be shown to the customer's staff for human review only. They will not make or automate funding decisions, and each customer's signals will be generated from that customer's own data, not shared across customers.
  • Bank data connections. If and when enabled, a customer's applicants may choose to connect a bank account through a provider such as Plaid instead of uploading statements. The provider collects bank credentials and account data under its own privacy policy, and the account data it returns becomes Customer Data.
  • Identity verification with selfie and liveness checks. If and when enabled, a customer may ask an applicant or guarantor to take a selfie that is compared with an identity document. This can create biometric identifiers (such as face geometry). Before any biometric data is collected, the individual will receive written notice of the purpose and retention period and will be asked for written consent, as required by the Illinois Biometric Information Privacy Act, Texas and Washington biometric laws, and other laws. Biometric data will be used only for identity verification for that customer, will never be sold, leased, traded or used for profit, and will be permanently destroyed when the purpose is satisfied and no later than the earliest deadline set by applicable law (in Illinois, within 3 years after the individual's last interaction; in Texas, within 1 year after the purpose expires). We will publish a biometric data retention and destruction policy before this feature is enabled.
  • AI voice agents. If and when enabled, customers may use AI voice agents to place or answer calls. Each AI call will disclose at the start that the caller is an automated AI assistant acting for the named business. Customers must hold the prior express consent the law requires for artificial or prerecorded voice calls. See our AI Disclosures.
  • Point-of-sale connectors. If and when enabled, a customer may connect a merchant's point-of-sale or payment account, with the merchant's authorization, to import sales data as Customer Data.
  • Public API. If and when enabled, customers may connect other tools to Cheetah OS through an API. Data sent through the API at a customer's direction is governed by the customer's own arrangements with those tools.

13. How long we keep information

We keep personal information only as long as needed for the purposes in this policy, then delete or de-identify it. For information we control, our schedule is:

InformationHow long we keep it
Hashed IP addresses used for rate limitingUp to [[FILL: e.g. 24 hours]], then deleted
Site chat messages[[FILL: confirm whether stored, and period]]
Contact form submissions and prospect records24 months after our last interaction with you [[FILL: confirm]]
Demo accounts and their synthetic dataDeleted automatically when the demo expires [[FILL: demo lifetime]]
User account detailsFor the life of the customer's subscription, then deleted with the customer's tenant (see below)
Sign-in and security logs[[FILL: e.g. 12 months]]
Audit log records[[FILL: retention period]]
Billing and tax records7 years after the transaction [[FILL: confirm]]
Marketing opt-out (suppression) listAs long as needed to honor your opt-out
Privacy request records24 months
Staff and contractor recordsLength of the engagement plus the period required by tax and employment law [[FILL: confirm, e.g. 4 years]]

Customer Data is kept for as long as the customer keeps it in the Service. When a subscription ends, the customer's administrators can export its data for 30 days [[FILL: confirm]]. After that window we delete the customer's data and destroy its tenant encryption keys, which makes any remaining encrypted copies unreadable. Encrypted backups expire on our backup schedule [[FILL: backup retention period]]. We may keep information longer where the law requires it or where it is needed for an active legal claim.

14. How we protect information

We use administrative, technical and physical safeguards designed to protect personal information. Today they include:

  • Tenant isolation. Each customer's data is separated from every other customer's data, and access is checked against the User's organization and role.
  • Per-tenant encryption keys. Each customer's sensitive data is encrypted with keys unique to that customer.
  • Field-level encryption. Sensitive fields, such as national identifiers, are encrypted individually in addition to encryption of the underlying storage.
  • Encrypted document storage. Uploaded documents are stored in Amazon Web Services S3 and encrypted using keys managed through AWS Key Management Service.
  • Encryption in transit. Connections to the Site and the Service use TLS.
  • Tamper-evident audit log. Significant actions are written to a hash-chained log, so later changes to past entries can be detected.
  • Multi-factor authentication. Passkeys and time-based one-time passwords are supported. MFA is mandatory for our internal staff roles and available to every customer User. We strongly recommend that customers require it for their teams.
  • Breached-password screening. New passwords are checked against lists of known breached passwords, using a method that never sends your password.
  • Malware scanning of uploaded files.
  • Least-privilege access. Our staff and systems get only the access they need.
  • Bot protection on forms through Cloudflare Turnstile.

No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorization. Section 22 explains what we do if it is.

15. International transfers

We are based in the United States, and we and our sub-processors store and process information in the United States [[FILL: confirm Neon, Vercel and S3 regions]]. If you are outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those where you live.

For personal information subject to UK data protection law, we rely on [[FILL: the UK Extension to the EU-US Data Privacy Framework if Cheetah Technologies LLC self-certifies]] or on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. For personal information subject to EU law, we would rely on the EU Standard Contractual Clauses [[FILL: or the EU-US Data Privacy Framework if certified]]. You can ask us for a copy of the relevant safeguards using the contact details below.

16. Children

The Site and the Service are for business use by adults. We do not knowingly collect personal information from anyone under 18, and customers agree not to upload information about children. If we learn that we hold a child's information as a controller, we will delete it.

17. Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. Cheetah OS does not approve, decline or price financing. Where the Service scores, ranks or flags information, the output is presented to a person at the customer, who makes the decision. Customers are responsible for how they use Service outputs in their own decisions.

18. Global Privacy Control and cookies

The Site uses only strictly necessary cookies and similar technologies, and no analytics or advertising trackers. We honor Global Privacy Control (GPC) and similar opt-out preference signals as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for that browser and, if you are signed in, for your account. Because we do not sell or share personal information, a GPC signal does not change how the Site works for you. Details are in our Cookie Notice.

19. Your US state privacy rights

Rights we offer

Depending on where you live, you may have the right to:

  • Know and access the personal information we hold about you, including the categories, sources, purposes and recipients, and to receive a copy in a portable format;
  • Correct inaccurate personal information;
  • Delete personal information;
  • Opt out of the sale or sharing of personal information, targeted advertising, and profiling that produces legal or similarly significant effects (we do none of these);
  • Limit the use of sensitive personal information (we already limit it, see Section 9);
  • Obtain a list of the specific third parties to which we have disclosed personal information, where state law provides it (for example Oregon);
  • Question the result of profiling and learn the reasons for it, where state law provides it (for example Minnesota); and
  • Not be discriminated against for exercising these rights.

We will respond to requests from residents of any US state, whether or not a specific state law applies to the request.

California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to California residents, including people acting in a business-to-business or employment context. That means it covers California residents who are our prospects, customer Users, billing contacts, staff and contractors.

Notice at collection. In the past 12 months we have collected the following categories of personal information as a controller. We have not sold or shared any of them.

CategoryExamplesSourcesPurposes (Section 5)Disclosed for a business purpose toRetention
IdentifiersName, work email, phone number, IP address, account IDYou, your organization, your browser1 to 10Hosting, database, email, error monitoring, bot protection, AI chat providersSection 13
Customer records (Cal. Civ. Code 1798.80(e))Name, address, phone, billing details, and for staff, bank detailsYou, Stripe2, 4, 9, 10Stripe, hosting and database providersSection 13
Commercial informationSubscription plan, invoices, payment statusYou, Stripe4, 9StripeSection 13
Internet or other electronic network activityPages requested, device and browser data, sign-in events, audit log entries, hashed IP for rate limitingYour browser, the Service1, 2, 7, 8Hosting, database, error monitoring and bot protection providersSection 13
Audio, electronic or similar informationMessages you type into the Site chat, support messagesYou3Groq (Site chat), email providerSection 13
Professional or employment-related informationJob title, employer, and for staff, engagement recordsYou, your organization1, 2, 10Hosting and database providersSection 13
Characteristics of protected classificationsStaff only: tax forms may reveal marital statusStaff10Payroll and tax providers [[FILL: confirm]]Section 13
Sensitive personal informationAccount sign-in credentials; staff only: Social Security number, government identity documents, bank account detailsYou, staff2, 7, 10Hosting and database providersSection 13

We do not collect precise geolocation, biometric information, health information, or education records as a controller, and we do not create inferences or profiles about you.

Right to limit. We use sensitive personal information only for the purposes permitted by California regulations without a right to limit, so we do not offer a separate "Limit the Use of My Sensitive Personal Information" link.

Customer Data. For Customer Data, we act as a service provider to our customers. California residents whose information is in Customer Data should contact the customer, as explained in Section 21.

Other states

Comprehensive privacy laws in Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Nebraska, Maryland, Minnesota, Kentucky and Rhode Island, and from 2027 Oklahoma, Louisiana and Alabama, and from 2028 Vermont, give residents rights similar to those listed above. Many of these laws do not apply to individuals acting in a commercial or employment context, and many apply only to businesses above certain size thresholds. We honor requests from residents of these states anyway. We do not sell personal data, including sensitive data, and we do not process personal data for targeted advertising or for profiling in furtherance of decisions that produce legal or similarly significant effects. We do not use personal data to train large language models.

How to make a request

  • Email privacy@cheetahos.app [[FILL: confirm mailbox exists]], or write to us at the address in the Contact section.
  • Tell us your name, email address, state or country of residence, and the right you want to exercise.
  • Verification. We will verify your identity by matching the information you give us to information we hold, for example by confirming control of the email address on your account. We will ask for no more information than we need, and we will use it only for verification.
  • Authorized agents. You may use an authorized agent. We may ask the agent for signed permission from you and may ask you to verify your identity directly.
  • Timing. We will confirm receipt within 10 business days and respond within 45 days. If we need more time, we will tell you why, and the total will not exceed 90 days.
  • Cost. Requests are free, unless they are manifestly unfounded or excessive.

Appeals

If we decline to take action on your request, we will explain why. You can appeal by emailing privacy@cheetahos.app with the subject line "Privacy appeal" within 60 days of our decision. A person who was not involved in the original decision will review it, and we will respond in writing within 45 days, explaining what we did and why. If your appeal is denied, you may contact your state attorney general. In California, you may also contact the California Privacy Protection Agency.

20. UK and EU privacy rights

When UK and EU law apply

The UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, apply to our processing of personal information of people in the United Kingdom when we offer the Service in the UK. We do not currently target individuals in the European Union. If EU law applies to our processing of your information, you have the equivalent rights under the EU General Data Protection Regulation.

Your rights

Subject to conditions and exceptions in the law, you have the right to:

  • access your personal information and receive a copy;
  • have inaccurate information corrected;
  • have your information erased;
  • restrict how we use your information;
  • receive your information in a portable format and have it sent to another organization;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing, which we will always honor;
  • not be subject to a significant decision based solely on automated processing without safeguards, and to make representations, obtain human intervention and contest such a decision (we do not make such decisions, see Section 17); and
  • withdraw consent at any time, where we rely on consent.

We will respond within one month. For complex or numerous requests, we may extend this by up to two further months and will tell you why. The time limit pauses while we ask you for information we reasonably need to find your data or confirm your identity.

Complaints

You can complain to us first. Email privacy@cheetahos.app or write to us at the address below. We will acknowledge your complaint within 30 days, investigate it without undue delay, and tell you the outcome.

You also have the right to complain to the UK data protection regulator: the Information Commissioner's Office, which becomes the Information Commission on 30 September 2026, at ico.org.uk. Our registration number with the regulator is [[FILL: ICO registration number]]. If EU law applies, you may complain to the data protection authority in the EU country where you live or work.

Our representatives

Our UK representative under Article 27 of the UK GDPR is [[FILL: name and UK address of UK representative]]. You can contact our representative instead of us about any UK data protection matter. [[FILL: EU representative name and address, only if Cheetah targets the EU]].

21. If a Cheetah OS customer holds your information

If you are a merchant, business owner, guarantor, lead, call recipient, investor, or a customer's staff member, the business you dealt with controls your information, not Cheetah. To access, correct or delete it, or to ask how it is used, please contact that business directly.

If you contact us instead, we will tell you that we act for the customer, forward your request to the customer within [[FILL: e.g. 10 business days]] where we can identify it, and help the customer respond. We will not act on the request ourselves unless the customer instructs us to or the law requires it. To opt out of calls or texts from one of our customers, reply STOP to a text or tell the caller you do not want further calls, and the customer's opt-out will be recorded in the Service.

22. Security incidents

If we become aware of a breach of security leading to unauthorized access to, or accidental or unlawful destruction, loss, alteration or disclosure of, personal information we process for a customer, we will notify the affected customer without undue delay, and in any case within 72 hours after confirming the incident [[FILL: counsel may shorten]]. We will give the customer the information it needs to meet its own notification duties and will update it as we learn more. For personal information we control, we will notify affected individuals and regulators as the law requires. We will not make public statements about an incident until the facts are verified, and we will correct any statement if the facts change.

23. Changes to this policy

We may update this policy as the Service or the law changes. We will post the updated version here with a new "Last updated" date. For material changes, we will notify customer administrators by email or in the Service at least 30 days [[FILL: confirm]] before the change takes effect. We will not make a material change to how we use personal information already collected, such as using it to train AI models, without the affirmative consent the law requires.

Contact

Cheetah Technologies LLC [[FILL: mailing address]]