Beta coming soon. Join the release list below.

Legal

Draft pending counsel review. This page previews an updated document and is not yet in effect. Until it takes effect, the previously published FrugalAI terms continue to apply. Questions: legal@frugalai.io.

Data Processing Agreement

Effective date: accepted with the FrugalAI Terms of Service · Version: 1.0-draft

This DPA forms part of the FrugalAI Terms of Service (the "Agreement") between Jake Bauman d/b/a FrugalAI ("FrugalAI," the "Processor") and the customer ("Customer") and applies whenever FrugalAI processes Personal Data contained in Customer Content on Customer's behalf. A countersigned copy is available on request to legal@frugalai.io.

1. Definitions

"Personal Data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings in applicable Data Protection Law. "Data Protection Law" means all privacy laws applying to the processing, including the EU and UK GDPR and the CCPA/CPRA. "SCCs" means the EU Commission Standard Contractual Clauses (2021/914). "Customer Content" is defined in the Agreement.

2. Roles and scope

Customer is the controller (or a processor acting for its own controllers, in which case FrugalAI is a subprocessor and Customer warrants its instructions are authorized). FrugalAI is the processor. Annex I describes the processing. This DPA does not apply to data for which FrugalAI is an independent controller (account, billing, telemetry, and site data, per the Privacy Policy).

3. Instructions

FrugalAI will process Customer Content only on Customer's documented instructions, which are: the Agreement, Customer's configuration of the Service (providers, policies, caching, data-minimization toggles), and its use of the APIs; and as required by law, in which case FrugalAI will inform Customer before processing unless the law prohibits it. FrugalAI will inform Customer if an instruction, in its opinion, violates Data Protection Law. FrugalAI does not train models on Customer Content and does not sell it.

4. Confidentiality

Persons authorized to process Customer Content (currently the founder and any future personnel or contractors) are bound by confidentiality obligations.

5. Security

FrugalAI implements the technical and organizational measures in Annex II and will not materially reduce the overall protection during the term. Customer is responsible for its own configuration choices (including enabling prompt previews or cached prompt text), the security of its systems and BYOK Keys outside the Service, and instructing its users not to submit Personal Data that the Service does not need, including special categories of data.

6. Subprocessing

Customer generally authorizes the subprocessors listed at frugalai.io/subprocessors (Annex III). FrugalAI will give at least 30 days notice (by updating that page and emailing billing contacts or its notification list) before adding or replacing a subprocessor that processes Customer Content. Customer may object on reasonable data-protection grounds within the notice period; if FrugalAI cannot offer a reasonable alternative (including configuration that avoids the subprocessor), Customer may terminate the affected subscription with a pro-rata refund of prepaid, unused fees. FrugalAI imposes data-protection obligations materially equivalent to this DPA on subprocessors and remains liable for their performance.

7. Data subject requests

Taking into account the nature of the processing, FrugalAI will assist Customer by appropriate technical and organizational measures in fulfilling data subject requests. If a data subject contacts FrugalAI directly about Customer Content, FrugalAI will redirect them to Customer and not respond substantively except as legally required. Note that by default FrugalAI stores hashes rather than prompt content, so content-level requests are typically actioned in Customer's own systems.

8. Assistance

FrugalAI will provide reasonable assistance with Customer's security, breach-notification, data-protection impact assessment, and prior-consultation obligations (GDPR Arts. 32-36), considering the information available to it. Assistance beyond what is reasonable for a self-serve service may be charged at a reasonable rate with advance notice.

9. Personal Data breach

FrugalAI will notify Customer without undue delay, and in any case within 72 hours, after confirming a Personal Data breach affecting Customer Content, at the account and billing email addresses. The notice will describe, to the extent known, the nature of the breach, categories and approximate volume affected, likely consequences, measures taken or proposed, and a contact point, and will be supplemented as information develops. Notification is not an admission of fault.

10. Deletion and return

During the term, Customer can delete cached content by disabling or expiring caches and can request deletion of specific records via privacy@frugalai.io. Within 30 days after termination, FrugalAI will, at Customer's choice, delete or return available Customer Content and delete remaining copies, except where law requires retention, and will confirm deletion in writing on request. Residual copies in backups age out within the backup retention window (35 days or less) and are protected until then.

11. Audits

FrugalAI will make available information reasonably necessary to demonstrate compliance with this DPA: this DPA, the security documentation at frugalai.io/security, subprocessor audit reports it holds (Annex III), and written responses to a reasonable security questionnaire, no more than once per 12 months, at Customer's expense beyond the first 4 hours. Where Data Protection Law grants Customer a mandatory audit right that these materials do not satisfy, an audit may be conducted with 30 days notice, during business hours, without access to other customers' data, under confidentiality, at Customer's cost.

12. International transfers

For transfers of EEA Personal Data to FrugalAI in the United States, the SCCs, Module Two (controller to processor), are incorporated by reference and are entered into between Customer (data exporter) and FrugalAI (data importer), completed as follows: Clause 7 (docking) is included; Clause 9(a) uses Option 2 (general authorization, 30 days); the optional language in Clause 11(a) is not included; Clause 13 and Annex I.C: the supervisory authority of the exporter's establishment; Clause 17: Option 1, Irish law; Clause 18(b): the courts of Ireland. Annexes I and II of the SCCs are the Annexes of this DPA. Where Customer acts as processor for its own controllers, Module Three applies with the same selections.

For UK transfers, the UK International Data Transfer Addendum (version B1.0) is incorporated; Tables 1-3 are completed by the details in this DPA and its Annexes, and neither party may terminate under Table 4 except as the Addendum requires. For Swiss transfers, the SCCs apply adapted as required by the FDPIC (references to the GDPR read as the Swiss FADP; the competent authority is the FDPIC; Swiss law governs where mandatory).

If a required transfer mechanism is invalidated, the parties will cooperate in good faith to adopt a replacement. FrugalAI will notify Customer if it becomes certified under the EU-U.S. Data Privacy Framework, which would then apply as an additional or alternative mechanism.

13. CCPA service provider terms

Where the CCPA/CPRA applies, FrugalAI is a "service provider": it will not sell or share Customer Content Personal Data; will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes in Annex I (and as permitted by regulation); will not combine it with data from other sources except as permitted; will comply with the CCPA; will notify Customer if it can no longer comply; and grants Customer the right to take reasonable steps to stop and remediate unauthorized use.

14. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Law prohibits that limitation (including as between the parties under the SCCs, whose terms prevail over this DPA and the Agreement in case of conflict for the transfers they govern). This DPA otherwise prevails over the Agreement for processing of Customer Content.


Annex I - Description of processing

A. Parties. Data exporter: Customer (contact per its account). Data importer: Jake Bauman d/b/a FrugalAI, [BUSINESS ADDRESS], California, USA, privacy@frugalai.io. Activities: FinOps control plane for AI model traffic. Role: processor.

B. Processing. *Data subjects:* Customer's personnel and end users whose data appears in Customer Content. *Categories:* any personal data Customer chooses to route through the gateway inside prompts, tool arguments, or model responses; account identifiers of Customer personnel. Customer is instructed to minimize personal data, and special categories are neither sought nor required by the Service. *Frequency:* continuous, per API request. *Nature and purpose:* receiving requests, routing to Customer-configured model providers, optional caching of responses, optional embeddings and sampled quality evaluation, spend metering, budget enforcement, and a decision ledger. By default prompt content is not stored (hash only); response caching stores responses; previews and cached prompt text are off by default. *Duration:* the subscription term plus the deletion period in Section 10. *Retention:* per the schedule in the Privacy Policy. *Transfers to subprocessors:* Annex III, for the purposes listed there.

C. Competent supervisory authority. Determined per Clause 13 of the SCCs (the exporter's authority).

Annex II - Technical and organizational measures

Implemented today: AES-256-GCM encryption of stored provider (BYOK) keys, encrypted before database write, decrypted only inside the gateway, never sent to browsers; gateway virtual keys stored as one-way SHA-256 hashes, plaintext shown once; production fails closed if the master encryption key is absent or a known development value; TLS for all data in transit; encryption at rest via the hosting platforms; prompt content not persisted by default (SHA-256 hash only); prompt previews and cached prompt text off by default and passed through secret-pattern redaction when enabled; cache isolation per organization with scope hashing over system prompt, model tier, temperature band, and response format, and organization-filtered lookups; tool-calling requests bypass caching; no card data touches FrugalAI systems (Stripe); webhook signature verification with a durable idempotency ledger; per-organization membership model with server-derived authorization; row-level security policies on tenant tables; security headers (CSP, HSTS, and related) on the dashboard; no IP, user-agent, or device capture in gateway telemetry; least-privilege access limited to the operator.

Planned and scheduled (tracked in the FrugalAI security roadmap, dates in the trust file): versioned master-key rotation with per-record key derivation and authenticated binding to organization and provider; automated retention purges; centralized monitoring, alerting, and audit logging; independent penetration testing; documented backup restore drills with stated RTO/RPO.

Organizational: single-operator business today; personnel expansion will add confidentiality agreements, access reviews, and role separation before any third party receives access. Incident response plan per the FrugalAI incident-response runbook.

Annex III - Subprocessors

The live list, including entity names, purpose, data processed, and location, is maintained at frugalai.io/subprocessors and currently comprises: Supabase (database, authentication; US), Vercel (dashboard hosting; US, global edge), Cloudflare (gateway runtime; global edge), Stripe (payments; US), OpenAI (semantic-cache embeddings and sampled quality judging, when enabled; US), Resend (transactional email; US).

Version 1.0-draft · sha256 02e14fd797a2