Customer Data Processing & Data Security Addendum
1. Purpose
This Data Processing Addendum ("DPA") establishes responsibilities regarding Customer Data processed through Cheetah Smart ERP.
2. Roles
Customer determines what business information is entered into the Service and why it is used. Cheetah processes Customer Data primarily to provide the Service.
3. Customer Ownership
Customer retains ownership of Customer Data. Nothing in this DPA transfers ownership of Customer Data to Cheetah.
4. Permitted Processing
Cheetah may process Customer Data for hosting, storage, retrieval, transmission, backup, security, technical support, troubleshooting, Service operation, maintenance, fraud prevention, performance monitoring, and Service improvement.
5. Confidentiality
Cheetah will require personnel and contractors with access to Customer Data to maintain appropriate confidentiality obligations.
6. Security Measures
Cheetah will implement reasonable security measures appropriate to the Service, which may include encryption in transit, encryption at rest where supported, access controls, authentication controls, password protection, role-based permissions, monitoring, backup procedures, security updates, restricted administrative access, and incident-response procedures.
7. Payment Information
Cheetah's application is not intended to store complete credit-card numbers, CVV codes, or bank-account credentials.
Payment information is processed through designated payment providers. Cheetah may retain payment-related identifiers and limited billing information necessary to operate subscriptions.
8. Data Segregation
Cheetah will use reasonable technical measures designed to prevent one customer's account from accessing another customer's Customer Data.
9. Security Incidents
If Cheetah determines that a security incident materially affecting Customer Data has occurred, Cheetah will take reasonable steps to investigate, contain, and remediate the incident.
Where required by applicable law, Cheetah will provide notice to affected customers or governmental authorities.
10. Data Export
Cheetah provides data-export/download functionality through the main administrative area. Customer is responsible for using these tools to maintain copies of critical business information.
11. Data Deletion
Following termination, Customer Data remains available for seven (7) days for Customer export through available administrative download tools.
After seven (7) days, Customer Data may be deleted. Backup copies may remain temporarily until overwritten through the normal backup cycle, which may be approximately thirty (30) days.
12. Third-Party Providers
Cheetah may engage third-party infrastructure and service providers for hosting, storage, payment processing, communications, security, analytics, and related services.
13. Customer Responsibilities
Customer is responsible for determining what information should be entered into Cheetah, obtaining appropriate permissions, maintaining accurate information, configuring user permissions, protecting credentials, complying with applicable laws, and maintaining independent records of critical information.
14. No Absolute Security Guarantee
Customer acknowledges that no electronic system can guarantee absolute security. Cheetah does not guarantee that Customer Data can never be accessed, lost, corrupted, altered, or disclosed as a result of circumstances beyond Cheetah's reasonable control.
15. Governing Documents
If there is a conflict between this DPA and the Terms of Service concerning Customer Data, this DPA controls solely with respect to the specific data-processing issue.