factual

What is the impact on Acumera's liability if the Acumera-provided firewall has been circumvented at a Dq Treat location?

Dq_Treat Franchise · 2025 FDD

Answer from 2025 FDD Document

  • Managed Firewall/SD-WAN Exclusions In no event shall Acumera have any liability to Participating Location for any data breach that occurs:

  • during any period in which the Acumera-provided or Acumera-approved firewall or SD-WAN device

has yet to be initially connected or is disconnected or has been circumvented;

  • i. due to the failure to implement a security measure as recommended by PCI-DSS Standards;

  • j. in any Participating Location environment where POS system data traffic is not configured to be on an isolated network segment through the Acumera firewall;

  • k. when Participating Location requests that the isolated network segment containing POS data traffic is granted access to any system or service not directly related to processing POS transactions.

However, this exclusion will not apply unless Participating Location received a Configuration Exception from Dairy Queen;

  • I. when Dairy Queen mandates implementation of a configuration, policy or procedure that Acumera recommends against (if Dairy Queen has been notified of the recommendation);

  • m. through any firewall in use, whether provided by Acumera or otherwise acquired by Participating Location, that has not passed its most recent Approved Scanning Vendor's scan (unless the issue has already been remediated);

  • n. in a manner that industry-standard firewall technology employed at time of breach is not able to prevent.

Source: Item 17 — The following paragraph is added to the end of Item 17 of the Disclosure Document: (FDD pages 70–378)

What This Means (2025 FDD)

According to Dq Treat's 2025 Franchise Disclosure Document, Acumera bears no liability to a participating Dq Treat location if a data breach occurs during any period in which the Acumera-provided or Acumera-approved firewall or SD-WAN device has been circumvented. This means that if a franchisee bypasses or disables the security measures put in place by Acumera, Acumera is not responsible for any resulting data breach. This lack of liability extends to various scenarios, including when the firewall is disconnected or has yet to be initially connected.

This exclusion of liability also applies if the data breach is due to a failure to implement a security measure as recommended by PCI-DSS Standards, or in any environment where POS system data traffic is not configured to be on an isolated network segment through the Acumera firewall. Similarly, if the franchisee requests access to any system or service not directly related to processing POS transactions, Acumera is not liable, unless the Participating Location received a Configuration Exception from Dairy Queen. Furthermore, Acumera is not liable if Dairy Queen mandates a configuration, policy, or procedure that Acumera recommends against, provided Dairy Queen has been notified of the recommendation.

Additionally, Acumera is not liable if the breach occurs through any firewall in use that has not passed its most recent Approved Scanning Vendor's scan, unless the issue has already been remediated, or if the breach occurs in a manner that industry-standard firewall technology employed at the time of the breach is not able to prevent. This comprehensive exclusion of liability highlights the importance of maintaining the integrity and proper configuration of the Acumera-provided firewall and adhering to recommended security measures to protect against data breaches at Dq Treat locations.

Disclaimer: This information is extracted from the 2025 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.