Data Processing Agreement
This page is the public summary of Dracon's Data Processing Agreement ("DPA"). The DPA forms part of the Dracon Omega subscription terms and applies whenever Dracon processes personal data on behalf of a customer in connection with the Dracon services.
Want the full signed DPA? Email legal@dracon.uk with your company name, the email on your account, and the words "DPA request" in the subject line. We send back a counter-signed PDF within 5 business days.
1. Scope
This DPA covers personal data that Dracon processes on behalf of customers in connection with:
- Dashboard — authentication, profile, billing, and API key management.
- Dracon Omega — the shared AI credit pool that powers Dracon's products.
- AI Hub — provider directory, plan comparison, and the request router that maps a Dracon request to a 3rd-party AI provider.
- SamAI, games, and the browser extensions — usage telemetry and crash reports.
It does not cover data you choose to send directly to a 3rd-party AI provider using your own API key (BYOK); that data flows directly between you and the provider and is governed by their terms.
2. Roles
Dracon is the Data Processor. The customer is the Data Controller. Dracon processes personal data only on the documented instructions of the customer (the subscription terms, the in-product consent flows, and any per-customer configuration), and only to the extent necessary to provide the services.
3. Sub-processors
Dracon uses the following sub-processors to provide the services:
- Turso — primary database (hosted SQLite, EU and US regions).
- Cloudflare — DNS, edge cache, and DDoS protection.
- Stripe / Paddle — payment processing (whichever is the active billing provider for your account).
- A managed transactional-email provider — magic-link sign-in, billing receipts, and security alerts.
- Artificial Analysis — the public AI provider rankings feed that powers /ai-hub.
Dracon will notify customers at least 30 days before adding a new sub-processor. Customers may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the customer may terminate the affected service for a pro-rated refund.
4. Data residency
Customer data is stored in the region selected at sign-up (EU or US). A cross-region copy may exist for disaster recovery; copies are encrypted and access is limited to operations staff.
5. Security
Dracon maintains administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, audit logging, and incident response. The full controls catalog is on the /security page.
6. Sub-processor data requests & government access
Dracon will challenge any government or law-enforcement request for customer data that it considers over-broad, and will notify the affected customer before disclosing data unless legally prohibited from doing so. The /compliance page lists the categories of requests received and Dracon's response.
7. Data subject requests
Dracon will assist the customer in responding to data-subject requests (access, deletion, portability) by providing the tooling needed to act on those requests directly in the dashboard, or by processing bulk requests on the customer's behalf within 30 days.
8. Term & termination
This DPA is in effect for as long as Dracon holds customer personal data. On termination of the subscription, Dracon will delete customer personal data within 90 days except where retention is required by law (e.g. tax records).
9. Contact
Questions about this DPA, or to request a counter-signed copy, email legal@dracon.uk.