CHEETAH SMART
Legal

Customer Data Processing & Data Security Addendum

Effective Date: August 26, 2026
Part of a five-document set: Terms of Service · Privacy Policy · Subscription, Billing & Cancellation Terms · Acceptable Use & Customer Responsibility Policy · Data Processing & Security Addendum

1. Purpose

This Data Processing Addendum ("DPA") establishes responsibilities regarding Customer Data processed through Cheetah Smart ERP.

2. Roles

Customer determines what business information is entered into the Service and why it is used. Cheetah processes Customer Data primarily to provide the Service.

3. Customer Ownership

Customer retains ownership of Customer Data. Nothing in this DPA transfers ownership of Customer Data to Cheetah.

4. Permitted Processing

Cheetah may process Customer Data for hosting, storage, retrieval, transmission, backup, security, technical support, troubleshooting, Service operation, maintenance, fraud prevention, performance monitoring, and Service improvement.

5. Confidentiality

Cheetah will require personnel and contractors with access to Customer Data to maintain appropriate confidentiality obligations.

6. Security Measures

Cheetah will implement reasonable security measures appropriate to the Service, which may include encryption in transit, encryption at rest where supported, access controls, authentication controls, password protection, role-based permissions, monitoring, backup procedures, security updates, restricted administrative access, and incident-response procedures.

7. Payment Information

Cheetah's application is not intended to store complete credit-card numbers, CVV codes, or bank-account credentials.

Payment information is processed through designated payment providers. Cheetah may retain payment-related identifiers and limited billing information necessary to operate subscriptions.

8. Data Segregation

Cheetah will use reasonable technical measures designed to prevent one customer's account from accessing another customer's Customer Data.

9. Security Incidents

If Cheetah determines that a security incident materially affecting Customer Data has occurred, Cheetah will take reasonable steps to investigate, contain, and remediate the incident.

Where required by applicable law, Cheetah will provide notice to affected customers or governmental authorities.

10. Data Export

Cheetah provides data-export/download functionality through the main administrative area. Customer is responsible for using these tools to maintain copies of critical business information.

11. Data Deletion

Following termination, Customer Data remains available for seven (7) days for Customer export through available administrative download tools.

After seven (7) days, Customer Data may be deleted. Backup copies may remain temporarily until overwritten through the normal backup cycle, which may be approximately thirty (30) days.

12. Third-Party Providers

Cheetah may engage third-party infrastructure and service providers for hosting, storage, payment processing, communications, security, analytics, and related services.

13. Customer Responsibilities

Customer is responsible for determining what information should be entered into Cheetah, obtaining appropriate permissions, maintaining accurate information, configuring user permissions, protecting credentials, complying with applicable laws, and maintaining independent records of critical information.

14. No Absolute Security Guarantee

Customer acknowledges that no electronic system can guarantee absolute security. Cheetah does not guarantee that Customer Data can never be accessed, lost, corrupted, altered, or disclosed as a result of circumstances beyond Cheetah's reasonable control.

15. Governing Documents

If there is a conflict between this DPA and the Terms of Service concerning Customer Data, this DPA controls solely with respect to the specific data-processing issue.

This document was prepared to reflect Cheetah Smart ERP's actual data-handling setup and has not been independently reviewed by an attorney since this update.