Data Processing Agreement.
Effective2026-09-03Pisama · San Francisco
§ 01 · Requesting a DPAHow to request one.
To ask whether a Data Processing Agreement (DPA) can cover a proposed deployment, email with your company name and account email. A request does not itself establish GDPR compliance or guarantee that a DPA will be available for the requested scope.
§ 02 · What we processWhat we process.
Pisama processes LLM agent traces you submit via the API or SDK. These may contain conversation content, tool calls, and metadata. We process this data solely to provide the Pisama failure-detection service.
§ 03 · RetentionData retention.
The product manifest lists 14 days as a managed-preview reference allowance; this page does not assert operational enforcement. Actual retention, deletion, and backup behavior must be defined for the provisioned deployment. You may request deletion by emailing .
§ 04 · Sub-processorsSub-processors.
- Vercel (frontend hosting and edge delivery)
- Fly.io (backend application hosting and managed database)
- Brevo and Resend (configured transactional or request email delivery)
- Google (configured sign-in identity)
- PostHog, Google Analytics, and Vercel Analytics (when configured)
- Anthropic (only for configured model-assisted processing)
- Sentry (when configured for error and security monitoring)
© 2026 Pisama · San Francisco · Last updated 2026-09-03