Mandragora Labs
ApproachEngagementsFitFAQ
Request a Fit Call
HomeApproachEngagementsFit

Privacy

Privacy Policy

This Privacy Policy explains how Dragonfruit Ventures LLC, operating the Mandragora Labs brand (“Mandragora,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information through mandragoralabs.com, related communications, qualification activities, and services.

We apply this Policy according to the services and technology actually in use. It does not promise that every category or tool described below is active at all times.

Effective and last updated: August 12, 2026

On this page

ScopeInformation collectedHow information is usedAI-assisted processingDisclosureCookiesPrivacy rightsContact
01

Scope

This Policy applies to personal information we control through this website, scheduling and conversational interfaces, email, telephone and text communications, diagnostic intake, and our business relationship with prospects and clients.

It does not govern a client's independent data practices or third-party services you access under a separate account or relationship. When we process personal information solely on a client's instructions, the client may be the business or controller responsible for the applicable privacy notice, and our responsibilities will be defined in the relevant agreement.

02

Information we may collect

Depending on how you interact with us, we may collect:

  • Identifiers and contact details: name, business email, telephone number, postal address, IP address, and account or communication identifiers.
  • Professional and company information: title, role, employer, company size, industry, systems used, business priorities, and authority to evaluate or purchase services.
  • Communications: emails, messages, call notes, chatbot or AI-assistant conversations, scheduling information, feedback, and recordings when appropriate notice and consent are provided.
  • Diagnostic and operational information: workflow descriptions, business problems, process documents, system inventories, data-readiness observations, goals, constraints, and materials supplied for an assessment or engagement.
  • Device and usage information: browser and device type, operating system, referring page, pages viewed, approximate location derived from IP address, timestamps, interactions, cookie identifiers, and diagnostic logs.
  • Transaction and relationship information: services considered or purchased, invoices, payment status, contract records, support history, and client preferences. Payment-card details are ordinarily processed by the payment provider rather than stored by us.
  • Integration and security information: authorized system identifiers, configuration information, access logs, incident records, and credentials or tokens when an engagement requires them. Access to credentials is limited according to the engagement and should use secure transfer methods.

Do not submit sensitive personal information, regulated data, confidential third-party data, or production credentials through a general website field or conversational assistant unless we have specifically requested it and provided an appropriate secure method.

03

Sources of information

We may collect information directly from you or your organization; automatically through the Site; from authorized colleagues, referral partners, or service providers; from publicly available business sources; and from third-party systems you authorize us to access during an engagement.

04

How we use information

We use personal information when reasonably necessary to:

  • respond to inquiries and determine whether a fit call or paid diagnostic is appropriate;
  • schedule meetings, prepare and deliver services, administer agreements, process payments, and provide support;
  • understand business context, evaluate readiness, prepare recommendations, and coordinate authorized implementation work;
  • operate, secure, troubleshoot, measure, and improve our Site, communications, services, and internal processes;
  • send requested information and, where permitted, relevant business communications;
  • prevent fraud, misuse, security incidents, and violations of our terms;
  • maintain business, tax, legal, audit, and dispute records; and
  • comply with law and protect our rights, clients, users, and third parties.

Where a law requires a legal basis, we rely as applicable on consent, performance of a contract, steps requested before entering a contract, compliance with legal obligations, and legitimate business interests that are not overridden by your rights.

05

AI-assisted processing and conversational interfaces

We may use AI-assisted tools to classify inquiries, retrieve approved information, prepare summaries or draft responses, organize diagnostic inputs, and support service delivery. Information submitted to an AI interface may be sent to authorized technology providers that process it for us.

When a website conversation is handled by an AI assistant, the interface should identify that it is automated. We do not use the public website assistant to make final decisions about employment, housing, credit, insurance, medical care, legal rights, or another similarly consequential matter. A person may review conversations, correct output, qualify requests, and intervene when needed.

AI output can be wrong or incomplete. Do not rely on a website assistant for emergency, legal, financial, security, or other high-impact decisions.

06

How information may be disclosed

We may disclose information to:

  • Service providers and subprocessors supporting hosting, communications, scheduling, CRM, analytics, payments, document management, security, AI processing, and professional operations.
  • Professional advisers such as attorneys, accountants, insurers, auditors, and technical specialists subject to appropriate duties.
  • Client-authorized providers and systems when needed to evaluate, implement, or operate an agreed integration.
  • Authorities or affected parties when reasonably necessary to comply with law, respond to valid legal process, investigate misconduct, protect safety or rights, or address a security incident.
  • Transaction participants in connection with a financing, reorganization, merger, acquisition, or sale of relevant business assets, subject to appropriate confidentiality protections.

We do not sell personal information for money. We do not currently share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. If those practices change, we will update this Policy and provide any legally required choice mechanism before applying the change.

07

Cookies, analytics, and embedded technology

The Site may use essential storage needed for security, navigation, preferences, and requested features. When enabled, analytics and embedded services may use cookies or similar technologies to measure traffic, preserve attribution, enable scheduling, or operate conversational interfaces.

Nonessential technologies will be configured with consent controls where required. Browser settings can block or delete cookies, but doing so may affect functionality. Third-party embeds may also collect information under their own privacy policies.

08

Email, telephone, and text communications

We may contact you to respond to a request, administer an engagement, provide service notices, or send communications you requested or that applicable law permits. Where prior consent is required for automated marketing calls or texts, we will seek that consent separately; consent is not a condition of purchase.

You may unsubscribe from marketing email through the provided link. For applicable text messages, reply STOP to opt out and HELP for assistance. Message and data rates may apply. Transactional or service communications may continue when reasonably necessary for an active relationship.

09

Retention

We retain personal information only for as long as reasonably necessary for the disclosed purpose, an active prospect or client relationship, contractual commitments, security, dispute resolution, and legal, accounting, or reporting obligations. Retention varies by category, sensitivity, context, and applicable agreement. When information is no longer required, we take reasonable steps to delete, de-identify, or securely archive it.

10

Security and shared responsibility

We use reasonable administrative, technical, and organizational measures appropriate to the information and our role. Measures may include access controls, secure transfer methods, provider due diligence, environment separation, logging, backups, and human approval for sensitive actions where within scope.

No transmission, storage method, model, cloud provider, or integration can be guaranteed completely secure. Clients and users remain responsible for their own devices, networks, permissions, credentials, internal access, lawful instructions, and incident reporting. Security obligations for a paid engagement are defined by the signed documents and the technology actually selected.

11

Privacy rights and choices

Depending on your residence and the law that applies, you may have rights to request access to or a copy of personal information; correction; deletion; portability; restriction of certain processing; withdrawal of consent; opt-out from sale, sharing, or targeted advertising; limitation of certain sensitive-information uses; and appeal of a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.

Submit a request to privacy@dragonfruitventures.com. Describe the right you wish to exercise and the relevant interaction with us. We may need to verify your identity and authority before responding. An authorized agent may submit a request when legally permitted, but we may request proof of authorization and direct verification from the individual.

We will respond within the period required by applicable law. Certain information may be exempt—for example, when retention is required by law, needed to complete a transaction, necessary for security, or protected by another person's rights.

12

Children and international processing

The Site and services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children through the Site.

We currently serve the U.S. market, but service providers may process information in the United States or other locations. Where required, transfers will be handled under appropriate contractual or legal mechanisms.

13

Policy updates

We may revise this Policy as our Site, services, providers, or legal obligations change. The effective date above identifies the current version. We will provide additional notice when a material change requires it.

14

Contact and privacy requests

Questions, requests, or concerns may be sent to privacy@dragonfruitventures.com.

Dragonfruit Ventures LLC
Mandragora Labs — Privacy
412 N Main St., Suite 100
Buffalo, Wyoming 82834, USA
+1 (219) 271-7310
Mandragora Labs

AI Operations Integration for established businesses moving beyond scattered AI activity.

HomePrivacyTermsAI Ethics

Mandragora Labs is a brand operated by Dragonfruit Ventures LLC.

© 2026 Dragonfruit Ventures LLC. All rights reserved.