This Data Processing Addendum is part of the agreement between Texas Inference Inc ("Texas Inference") and the customer that signs it or accepts it online ("Customer"). It applies whenever Texas Inference processes personal data for Customer.
1. Scope and Precedence
1.1 This DPA covers two services. A lane runs a model for Customer's team on Texas Inference servers. A GPU rental gives Customer one to eight GPUs and a confidential virtual machine to run its own workload.
1.2 Where this DPA and the Terms of Service disagree on data protection, this DPA governs.
2. Definitions
2.1 Customer Content means everything Customer or its users send to a lane or place in a rental. That includes prompts, files, outputs, model state and any data inside a rental's virtual machine.
2.2 Account Data means what Texas Inference needs to run the account. That is names, work emails, titles, billing details, reservation records, signed documents and support messages.
2.3 Confidential Environment means a virtual machine whose memory Intel TDX encrypts. It runs on NVIDIA Blackwell GPUs with GPU memory encryption and encrypted NVLink. An attestation report signed by the hardware shows all three.
2.4 Data Protection Laws means every law that applies to the personal data processed under this DPA. That includes the Texas Data Privacy and Security Act, the California Consumer Privacy Act and the other US state privacy laws.
3. Roles
3.1 For Customer Content, Customer is the controller and Texas Inference is the processor. Where Customer is itself a processor for its own clients, Texas Inference is its subprocessor.
3.2 For Account Data, Texas Inference is a controller. The Privacy Policy covers that data. The rest of this DPA does not.
3.3 On a GPU rental, Texas Inference does not know what Customer runs or stores. Customer decides whether personal data goes into the rental at all.
4. Instructions
4.1 Texas Inference processes Customer Content only to provide the service Customer ordered and only on Customer's documented instructions. The agreement, this DPA and Customer's settings are those instructions.
4.2 Texas Inference tells Customer without undue delay if it believes an instruction breaks a Data Protection Law. It may then pause that instruction until Customer confirms or changes it.
4.3 No training. Texas Inference never uses Customer Content to train, fine tune, evaluate or improve any model. It never sells or shares Customer Content. It never combines Customer Content with data from anyone else.
5. Confidential Computing
5.1 Texas Inference processes Customer Content only inside a Confidential Environment. The memory of that environment is encrypted by the hardware while it runs.
5.2 Texas Inference personnel have no route to read Customer Content in plaintext while it is processed. No administrator console, log or support tool exposes Customer Content.
5.3 Customer may verify each session's attestation report with its own tools and without Texas Inference's involvement.
5.4 Confidential computing lowers risk. It does not remove it. A flaw in the hardware, the firmware or Texas Inference's own software could expose data. Texas Inference notifies Customer of any such flaw that affects the service under section 9.
6. Retention
6.1 Ephemeral lane. Texas Inference keeps no Customer Content after each request is answered.
6.2 Persistent lane. Texas Inference keeps Customer's working state only in encrypted memory and never writes it to disk. It drops that state after one hour without requests, on release of the lane or on Customer's request. Each drop is recorded.
6.3 GPU rental. Customer controls the data inside the rental. The rental's local disk is encrypted with a key that Customer holds. Texas Inference keeps no backup of it and cannot recover it. When the rental ends, Texas Inference erases the rental's memory and local storage before the GPUs serve anyone else.
6.4 Texas Inference keeps no logs of Customer Content. Operational logs hold timings, sizes, error codes and attestation results. They never hold prompts or outputs.
7. Processing Location
7.1 Texas Inference processes and stores Customer Content only in data centers located in the State of Texas.
7.2 Customer Content never leaves Texas. Texas Inference never moves work outside Texas for capacity. It queues or declines the work instead.
7.3 Account Data may be processed elsewhere in the United States by the subprocessors listed in Schedule 3.
7.4 This DPA covers Customer Content from the moment it reaches Texas Inference until it is answered, dropped or erased. This DPA does not cover Customer's storage of its data before or after that period.
8. Personnel and Subprocessors
8.1 Everyone at Texas Inference who can reach Customer's systems or Account Data is bound to confidentiality in writing.
8.2 Customer authorizes the subprocessors in Schedule 3. Texas Inference binds each one by written contract to the same duties it owes Customer under this DPA. Texas Inference remains liable for their acts and omissions.
8.3 No subprocessor is ever given access to Customer Content in plaintext. The operator of the data center provides space, power and network only. It has no logical access to any server and is not a subprocessor.
8.4 Texas Inference gives at least 30 days' notice by email before adding or replacing a subprocessor. Customer may object on data protection grounds within that time. The parties will work in good faith to resolve the objection. Customer may stop using the affected service if the objection is not resolved. The deposit terms govern any refund.
9. Security Incidents
9.1 Texas Inference notifies Customer within 48 hours after it confirms a breach of security that affects Customer Content or personal data in Account Data.
9.2 The notice describes the incident, the affected data, the steps taken and the steps Customer should take. Texas Inference updates it as facts emerge.
9.3 Texas Inference also notifies Customer within 48 hours after it learns of a hardware or firmware flaw that could expose Customer Content in a Confidential Environment.
9.4 Customer decides whether to notify regulators or individuals about Customer Content. Texas Inference assists on request.
10. Government and Legal Requests
10.1 Texas Inference notifies Customer of any legal demand for Customer Content before responding, unless the law forbids notice.
10.2 Texas Inference challenges any demand it believes is unlawful or too broad.
10.3 Texas Inference cannot produce Customer Content in plaintext. Customer Content exists only inside a Confidential Environment. Texas Inference holds no key to it and states this in any response.
11. Assistance
11.1 Texas Inference helps Customer answer requests from individuals exercising their privacy rights. It forwards any such request it receives to Customer and does not respond on its own.
11.2 Texas Inference gives Customer the information it needs for a data protection assessment under TDPSA or a similar law.
12. Audits
12.1 Texas Inference provides the information needed to show compliance with this DPA once a year on request. That includes its latest third party security reports once they exist.
12.2 Customer may audit Texas Inference once a year at its own cost on 30 days' notice. Texas Inference may instead provide a report from an independent assessor.
12.3 Customer may verify the attestation report for any session at any time without notice or cost.
13. Return and Deletion
13.1 When the service ends, no Customer Content remains to return. Ephemeral lanes keep none. Persistent lane state is dropped. Rentals are erased under section 6.3.
13.2 Texas Inference deletes Account Data within 30 days after the account closes. It keeps billing, tax, signed documents and dispute records for as long as the law requires.
14. US State Privacy Laws
14.1 Texas Inference acts as a processor and service provider for Customer Content. It does not sell or share Customer Content. It does not keep or use Customer Content outside the business purpose in this DPA. It does not combine Customer Content with other data.
14.2 Texas Inference will tell Customer if it can no longer meet these duties. Customer may then take reasonable steps to stop unauthorized use.
15. Liability, Governing Law and Changes
15.1 Liability under this DPA is subject to the limits in the Terms of Service.
15.2 Texas law governs this DPA.
15.3 Texas Inference may update this DPA. An update never lowers the protection Customer has. Customer receives 30 days' notice of any material change.
Schedules
Schedule 1. Details of Processing
| Item | Lane | GPU rental |
|---|---|---|
| Nature | Running a model on Customer's prompts and returning outputs | Hosting Customer's own workload in a confidential virtual machine |
| Purpose | Providing the lane Customer reserved | Providing the rental Customer reserved |
| Personal data | Whatever Customer puts in prompts and files | Whatever Customer places in the rental |
| Data subjects | Customer's staff, clients and anyone named in its content | Decided by Customer |
| Sensitive data | Only if Customer sends it. Health data needs a signed BAA. | Only if Customer places it. Health data needs a signed BAA. |
| Duration | The lane's term, with retention under section 6 | The rental's term, then erasure under section 6.3 |
| Location | Texas only | Texas only |
| Instructions | This DPA, the agreement and Customer's settings | This DPA, the agreement and Customer's configuration |
Schedule 2. Security Measures
| Area | Measure | Status |
|---|---|---|
| Memory encryption | Intel TDX encrypts the virtual machine's memory while it runs | Hardware feature |
| GPU encryption | Blackwell GPUs run in confidential computing mode with encrypted GPU memory | Hardware feature |
| GPU links | NVLink traffic between GPUs is encrypted | Hardware feature |
| Attestation | Every session comes with a report signed by Intel and NVIDIA that Customer can check with its own tools | |
| Transport | TLS that ends inside the Confidential Environment | |
| Isolation | One customer per lane at a time. A rental's GPUs serve no one else during its term | |
| No content at rest | Ephemeral lanes keep nothing. Persistent state stays in encrypted memory. No prompts or outputs in logs | |
| Erasure | Memory and local storage wiped between rentals, with a record | |
| Access control | Named staff only, hardware keys for sign in, access reviewed each quarter | |
| Physical | BBT data center in Midland, Texas, under BBT's physical security controls | |
| Change control | Every change to the software inside the Confidential Environment is reviewed and shows up as a new measurement in the attestation report | |
| Incidents | Written response plan, 48 hour notice under section 9 |
Schedule 3. Subprocessors
| Subprocessor | What it does | Data it sees | Where |
|---|---|---|---|
| Stripe | Payments and refunds | Account Data. Names, emails, bank details | United States |
| Convex | Reservation and account database | Account Data | United States |
| Railway | Hosts the website | Visitor requests. No Customer Content | United States |
| Notion | Internal records of reservations | Account Data | United States |
| Google Workspace | Sending and receiving mail | Account Data | United States |
No subprocessor listed here receives Customer Content.
Schedule 4. Contacts
Texas Inference: Cooper Scanlon, Founder. Send every notice, instruction and security report to [email protected].
Customer: the signer named in its order, unless it names someone else in writing.