Sub-processors
Last updated 2026-09-24
1. What this page covers
Cheetah Technologies LLC uses the providers below to run Cheetah OS and our website. Each is bound by a written contract that limits its use of personal information to providing services to us. For Customer Data, these providers are sub-processors under our Data Processing Addendum. How we use the information is explained in our Privacy Policy.
2. Sub-processors for the Cheetah OS application
| Provider | Purpose | Personal information involved | Location |
|---|---|---|---|
| Neon | PostgreSQL database hosting | All data stored in the Service; sensitive fields remain encrypted with per-tenant keys | United States [[FILL: confirm region]] |
| Vercel | Application hosting and content delivery | Request data and application data in transit | United States [[FILL: confirm region]] |
| Amazon Web Services (S3 and KMS) | Document storage and encryption key management | Uploaded documents, such as identity documents, bank statements and tax forms, stored encrypted | United States [[FILL: confirm region]] |
| Stripe | Subscription billing and payment methods | Billing contact details, payment method details (held by Stripe; we never store full card numbers), invoices | United States [[FILL: confirm]] |
| Telnyx | Voice calls, text messages, phone numbers and call recording | Phone numbers, call and message metadata, text message content, call recordings | United States [[FILL: confirm region]] |
| Resend | Transactional email delivery | Recipient email addresses and message content | United States [[FILL: confirm region]] |
| Sentry | Error monitoring | Technical error data, which may include User identifiers | United States [[FILL: confirm region]] |
| Cloudflare | Bot protection (Turnstile) on sign-in and forms | Browser and device signals, IP address | [[FILL: confirm]] |
| [[FILL: malware scanning provider]] | Malware scanning of uploaded files | Uploaded files | [[FILL: confirm]] |
| [[FILL: large language model provider]] | In-app AI assistant | The User's request and conversation, the User's name, role and organization name, and records the assistant looks up; not used to train models [[FILL: confirm no-training and retention terms]] | [[FILL: confirm]] |
3. Services a customer chooses to connect
These providers are used only if a customer connects its own account. They are the customer's own providers, and the customer's agreement with them governs their use of the data.
| Provider | When it is used | Personal information involved |
|---|---|---|
| When a customer connects a Google mailbox for email outreach, through OAuth or IMAP and SMTP | Mailbox authorization credentials (stored encrypted) and email sent or read through the connection | |
| Microsoft | When a customer connects a Microsoft mailbox for email outreach, through OAuth or IMAP and SMTP | Mailbox authorization credentials (stored encrypted) and email sent or read through the connection |
4. Providers for the cheetahos.app website
These providers process information about website visitors, for which we are the controller.
| Provider | Purpose | Personal information involved | Location |
|---|---|---|---|
| Vercel | Website hosting | Request data such as IP address and browser type | United States [[FILL: confirm region]] |
| Neon | Rate limiting records and demo account creation | A salted hash of the visitor's IP address; details entered in the demo form | United States [[FILL: confirm region]] |
| Cloudflare | Bot protection (Turnstile) on the contact and demo forms | Browser and device signals, IP address | [[FILL: confirm]] |
| Groq | AI inference for the "Ask our AI" chat | Messages the visitor types into the chat | [[FILL: confirm]] |
5. Planned providers
If and when we enable planned features such as bank data connections, identity verification, AI voice agents or point-of-sale connectors, we will add the providers involved to this page and give notice as described below before they process Customer Data.
6. Notice of changes
We will give customers at least 30 days' notice before a new sub-processor begins processing Customer Data, by [[FILL: notice method, e.g. email to customer administrators, plus an update to this page]]. Customers may object on reasonable data protection grounds within that period, as described in our Data Processing Addendum. To receive notices, [[FILL: describe how to subscribe, e.g. email privacy@cheetahos.app]].
Contact
Questions about our sub-processors: privacy@cheetahos.app [[FILL: confirm mailbox exists]] or info@cheetahos.app. Cheetah Technologies LLC, [[FILL: mailing address]].
