What is the impact on Acumera's liability if the Acumera-provided firewall is disconnected at a Dq Treat location?
Dq_Treat Franchise · 2025 FDDAnswer from 2025 FDD Document
Managed Firewall/SD-WAN Exclusions In no event shall Acumera have any liability to Participating Location for any data breach that occurs:
during any period in which the Acumera-provided or Acumera-approved firewall or SD-WAN device
has yet to be initially connected or is disconnected or has been circumvented;
i. due to the failure to implement a security measure as recommended by PCI-DSS Standards;
j. in any Participating Location environment where POS system data traffic is not configured to be on an isolated network segment through the Acumera firewall;
k. when Participating Location requests that the isolated network segment containing POS data traffic is granted access to any system or service not directly related to processing POS transactions.
However, this exclusion will not apply unless Participating Location received a Configuration Exception from Dairy Queen;
I. when Dairy Queen mandates implementation of a configuration, policy or procedure that Acumera recommends against (if Dairy Queen has been notified of the recommendation);
m. through any firewall in use, whether provided by Acumera or otherwise acquired by Participating Location, that has not passed its most recent Approved Scanning Vendor's scan (unless the issue has already been remediated);
n. in a manner that industry-standard firewall technology employed at time of breach is not able to prevent.
Source: Item 17 — The following paragraph is added to the end of Item 17 of the Disclosure Document: (FDD pages 70–378)
What This Means (2025 FDD)
According to Dq Treat's 2025 Franchise Disclosure Document, Acumera bears no liability to a participating Dq Treat location for any data breach that occurs during any period in which the Acumera-provided or Acumera-approved firewall or SD-WAN device has yet to be initially connected, is disconnected, or has been circumvented. This means that if a franchisee disconnects or bypasses the firewall provided by Acumera, Acumera is not responsible for any resulting data breaches.
This exclusion of liability also applies if a security measure recommended by PCI-DSS Standards is not implemented, or if POS system data traffic is not configured to be on an isolated network segment through the Acumera firewall. Similarly, if the participating location requests access to any system or service not directly related to processing POS transactions on the isolated network segment containing POS data traffic, Acumera is not liable, unless the Participating Location received a Configuration Exception from Dairy Queen.
Furthermore, Acumera is not liable if Dairy Queen mandates a configuration, policy, or procedure that Acumera recommends against, provided Dairy Queen has been notified of the recommendation. Acumera also has no liability for breaches occurring through any firewall that has not passed its most recent Approved Scanning Vendor's scan, unless the issue has been remediated, or in a manner that industry-standard firewall technology employed at the time of the breach is unable to prevent.
This limitation of liability underscores the importance of maintaining the Acumera-provided firewall and adhering to recommended security configurations. Dq Treat franchisees should ensure that their systems are properly configured and that they follow all security protocols to minimize the risk of data breaches and to ensure Acumera's liability exclusion does not apply.