Legal · Chompute Inference

Data Processing Addendum

The terms governing Dragonfruit AI's processing of personal data when customers use Chompute Inference.

Contracting entity
Dragonfruit AI, Inc.
Effective date
April 20, 2026
Product
Chompute Inference
Version
1.0

In short: Chompute Inference processes prompts and outputs transiently to provide inference and does not persist them. Dragonfruit retains usage and audit metadata as described below.

Effective April 20, 2026 · Version 1.0

This Data Processing Addendum (the “DPA”) forms part of the master services agreement, order form, online terms, or other written agreement governing Customer's use of Chompute Inference (the “Agreement”). It is entered into by Dragonfruit AI, Inc. (“Dragonfruit”) and the customer identified in the Agreement (“Customer”). It becomes binding when the Agreement incorporates it, an order form references it, or the parties otherwise agree to it in writing.

Capitalized terms not defined in this DPA have the meanings given in the Agreement. If there is a conflict concerning the processing of Personal Data, this DPA controls over the Agreement.

1.Scope and roles

1.1 Definitions

“Applicable Data Protection Law” means laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the EU ePrivacy Directive, the UK GDPR and Data Protection Act 2018, and applicable U.S. state privacy laws.

“Customer Content” means prompts, inputs, instructions, files, and other content submitted by or for Customer to Chompute Inference, together with the model output generated in response.

“Personal Data” means personal data, personal information, or a similar term protected by Applicable Data Protection Law that Dragonfruit processes on Customer's behalf.

“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Dragonfruit on Customer's behalf. It does not include unsuccessful attempts that do not compromise Personal Data.

“Usage Metadata” means operational, attribution, audit, security, and billing information about an inference request, excluding the contents of Customer prompts and model outputs.

1.2 Roles of the parties

For Personal Data processed under this DPA, Customer is a controller or business and Dragonfruit is its processor or service provider. If Customer acts as a processor for another controller, Dragonfruit acts as Customer's subprocessor. Each party will comply with the obligations applicable to its role.

1.3 Details of processing

Schedule 1 describes the subject matter, duration, nature, purpose, data types, data subjects, locations, and retention applicable to the processing.

2.Processing instructions

Dragonfruit will process Personal Data only to provide, secure, support, and improve Chompute Inference; to comply with the Agreement and Customer's documented instructions; and as required by law. The Agreement, this DPA, Customer's product configuration, and Customer's authorized use of the service constitute documented instructions.

If Dragonfruit believes an instruction infringes Applicable Data Protection Law, Dragonfruit will notify Customer unless prohibited by law and may suspend the affected processing until the parties resolve the issue. Customer is responsible for the lawfulness, accuracy, and quality of Personal Data and for providing all required notices and obtaining all required rights and consents.

Prompts and outputs are not persisted

Chompute Inference processes Customer Content transiently to generate and stream a response. Dragonfruit does not persist Customer prompts or model outputs in application databases, request logs, or audit records. Nothing in this DPA authorizes Dragonfruit to use Customer Content to train models.

3.Confidentiality and security

Dragonfruit will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and access Personal Data only as necessary to perform their duties. Dragonfruit will maintain appropriate technical and organizational measures designed to protect Personal Data against Security Incidents, as further described in Schedule 2.

Customer is responsible for configuring its account appropriately, protecting credentials and API keys, limiting the Personal Data it submits, and using the service consistently with the Agreement and Applicable Data Protection Law.

4.Subprocessors

Customer provides general authorization for Dragonfruit to engage subprocessors to provide compute, hosting, networking, security, monitoring, communications, billing, and support functions. Dragonfruit will enter into a written agreement with each subprocessor that imposes data-protection obligations materially equivalent to those in this DPA and will remain responsible for the subprocessor's performance of those obligations.

Dragonfruit will provide its current subprocessor list to Customer on written request. Dragonfruit will give Customer at least 15 days' prior notice before a new subprocessor begins processing Personal Data. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a commercially reasonable solution; if none is available, Customer may terminate the affected service without penalty.

5.Individual rights and assistance

Taking into account the nature of the processing, Dragonfruit will provide reasonable assistance to Customer with requests from individuals exercising rights under Applicable Data Protection Law. If Dragonfruit receives a request directly concerning Personal Data processed for Customer, Dragonfruit will direct the requester to Customer and will not respond substantively unless instructed by Customer or required by law.

Dragonfruit will also provide reasonable assistance with Customer's data protection impact assessments, prior consultations, security obligations, breach notifications, and regulator inquiries, taking into account the information available to Dragonfruit and the nature of its processing.

6.Security incidents

Dragonfruit will notify Customer without undue delay after confirming a Security Incident. The notice will include information reasonably available to Dragonfruit about the nature of the incident, categories of affected data and individuals, likely consequences, and measures taken or proposed. Dragonfruit may provide information in phases as it becomes available.

Dragonfruit will take reasonable steps to contain, investigate, and remediate the Security Incident and will reasonably cooperate with Customer. Notification is not an admission of fault or liability. Customer is responsible for notifications it is legally required to provide to individuals, regulators, or other third parties.

7.Deletion and retention

Customer Content is transient and is not retained after the inference response is completed. Usage Metadata is retained without a fixed expiration to support billing, customer attribution, security, abuse prevention, troubleshooting, service analytics, and auditability.

Dragonfruit will delete Customer's Usage Metadata when Customer explicitly requests deletion in writing. Dragonfruit will complete the request without undue delay, except to the extent retention is required by law, necessary to establish or defend legal claims, or present in secure backups awaiting deletion through Dragonfruit's ordinary backup cycle. Any retained data will remain protected by this DPA and will not be used for another purpose.

8.U.S. state privacy terms

To the extent U.S. state privacy law applies, Dragonfruit acts as a service provider or contractor for Customer. Dragonfruit will not:

  • sell or share Personal Data;
  • retain, use, or disclose Personal Data outside the direct business relationship with Customer or for a purpose other than the business purposes specified in the Agreement and this DPA;
  • combine Personal Data received from Customer with personal information received from another person or collected through Dragonfruit's own interaction with an individual, except as legally permitted to provide the service; or
  • use Personal Data for targeted or cross-context behavioral advertising.

Dragonfruit certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to verify that processing is consistent with Customer's obligations and to stop and remediate unauthorized use. Dragonfruit will notify Customer if it determines it can no longer meet these obligations.

9.International transfers

Dragonfruit may process Personal Data worldwide. Initial primary processing locations are the United States and India, and processing may occur in other countries where Dragonfruit or its authorized subprocessors operate. Dragonfruit will use a legally valid transfer mechanism where Applicable Data Protection Law restricts international transfers.

For restricted transfers from the European Economic Area, the 2021 EU Standard Contractual Clauses are incorporated as described in Schedule 3. For restricted transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses is also incorporated as described in Schedule 3.

10.Audits and information

Dragonfruit will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries of security controls, and independent assessment materials that Dragonfruit makes generally available to customers.

If that information is insufficient, Customer may conduct one audit per 12-month period, or more frequently following a Security Incident or regulator request. Audits require reasonable advance written notice, must occur during normal business hours, must avoid unreasonable disruption, and are subject to confidentiality and security requirements. Customer bears its audit costs unless the audit identifies a material breach by Dragonfruit. The parties will use remote review where it can reasonably satisfy the audit objective.

11.Government requests

Unless legally prohibited, Dragonfruit will notify Customer before disclosing Personal Data in response to a binding request from a public authority. Dragonfruit will review the legality of the request, challenge it when reasonable grounds exist, disclose only the minimum data legally required, and document its response.

12.General terms

The liability provisions, exclusions, and limitations in the Agreement apply to this DPA in the aggregate with the Agreement. Except for the transfer clauses, this DPA is governed by the law and dispute provisions in the Agreement. If there is no Agreement provision on governing law, California law applies and the state and federal courts located in Santa Clara County, California have exclusive jurisdiction.

If any provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions will continue in effect. This DPA survives termination for as long as Dragonfruit processes Personal Data on Customer's behalf. Dragonfruit may update this DPA to reflect changes in law or the service, but will not materially reduce Customer's data-protection rights during an active subscription without notice.

Schedule 1 — Processing details

Subject matter
Providing Chompute Inference and its associated account, metering, billing, security, support, and audit functions.
Duration
For the term of the Agreement and the retention period described in Section 7.
Nature and purpose
Receiving a prompt, routing and performing model inference, streaming the output, authenticating and attributing requests, measuring usage and cost, enforcing policy, securing and supporting the service, and maintaining audit records.
Frequency
Continuous or intermittent, depending on Customer's use of Chompute Inference.
Data subjects
Customer personnel, contractors, authorized users, end users, and other individuals whose Personal Data Customer includes in a prompt.
Customer Content
Prompts, inputs, instructions, and model outputs. Customer determines their contents. Customer Content is processed transiently and is not persisted.
Usage Metadata
Account, workspace, team, project, user, API-key, session, and request identifiers; IP address; timestamps; tool, model, route, request parameters, and policy events; token, byte, and character counts; non-reversible hashes; latency; status and error data; usage attribution; and cost and billing information. Usage Metadata excludes prompt and output contents.
Sensitive data
Chompute Inference is not designed to require special-category or highly sensitive Personal Data. Customer must not submit such data unless the parties expressly agree in writing on appropriate safeguards.
Retention
Customer Content: no persistence after completion of the inference response. Usage Metadata: retained without a fixed expiration unless Customer requests deletion in writing, subject to the limited exceptions in Section 7.
Processing locations
Worldwide. Initial primary locations are the United States and India.

Schedule 2 — Technical and organizational measures

Dragonfruit maintains measures appropriate to the nature of the service, the scope and context of processing, and the risks to individuals, including:

  • Data minimization. Customer Content is excluded from persistent application and audit storage; retained records are limited to Usage Metadata needed to operate and govern the service.
  • Access control. Role-based and least-privilege access, strong authentication, multi-factor authentication for privileged access, credential lifecycle controls, and periodic access review.
  • Encryption. Encryption of data in transit using industry-standard transport security and encryption of retained Personal Data at rest.
  • Infrastructure security. Network controls, environment separation, hardened systems, monitored administrative access, and protection against common attacks.
  • Logging and monitoring. Security and operational monitoring, audit trails for privileged activity, anomaly detection, and alerting appropriate to the service.
  • Secure development. Code review, change control, dependency and vulnerability management, security testing, and remediation processes.
  • Incident response. Documented detection, escalation, investigation, containment, recovery, and notification procedures.
  • Resilience. Backup, continuity, recovery, capacity, and availability procedures appropriate to retained systems and service commitments.
  • Personnel security. Confidentiality commitments, security and privacy training, and access removal upon role change or departure.
  • Vendor management. Risk-based diligence, contractual data-protection terms, and oversight of subprocessors.
  • Deletion. Procedures for responding to written deletion requests and securely deleting or rendering data unrecoverable when no longer required.
  • Testing. Periodic review and testing of the effectiveness of relevant technical and organizational measures.

Schedule 3 — International transfer terms

European Economic Area

For a restricted transfer subject to the EU GDPR, Commission Implementing Decision (EU) 2021/914 and its Standard Contractual Clauses (“EU SCCs”) are incorporated by reference. Module Two applies when Customer is a controller and Dragonfruit is a processor; Module Three applies when Customer is a processor and Dragonfruit is a subprocessor.

  • Clause 7 (docking) applies.
  • Clause 9 uses Option 2, with the 15-day notice period in Section 4.
  • The optional language in Clause 11 does not apply.
  • Under Clause 17, Option 1 applies and the governing law is Ireland.
  • Under Clause 18(b), disputes will be resolved by the courts of Ireland.
  • The competent supervisory authority under Clause 13 is determined by the EU SCCs.
  • Customer is the data exporter and Dragonfruit is the data importer. The Agreement and this DPA provide their contact information and activities relevant to the transfer.
  • Schedule 1 completes Annex I, Schedule 2 completes Annex II, and Dragonfruit's subprocessor list completes Annex III.

United Kingdom

For a restricted transfer subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 issued by the UK Information Commissioner and laid before Parliament on February 2, 2022 (the “UK Addendum”), is incorporated by reference. The information in this DPA and the Agreement completes Tables 1 through 3. In Table 4, either party may end the UK Addendum as permitted by Section 19 of its mandatory clauses.

If the EU SCCs, UK Addendum, or another transfer mechanism is invalidated or replaced, the parties will cooperate in good faith to implement a valid successor mechanism. The transfer terms control over conflicting provisions of the Agreement or this DPA for the relevant restricted transfer.

Dragonfruit AI, Inc.1070 Coleman AveMenlo Park, CA 94025United States
Privacy questionsprivacy@dragonfruit.aiChompute Inference