CallbackSign in

Privacy Policy

Version 1.0 · Effective July 7, 2026

This Privacy Policy explains how Pisama LLC ("Pisama", "we", "us"), the company that operates Callback Agent ("the Service"), collects, uses, shares, and protects personal data, and the rights you have over that data. It is written to align with the EU General Data Protection Regulation (GDPR), the UK GDPR and PECR, and the California Consumer Privacy Act as amended by the CPRA, alongside other US state privacy laws. Where a term has a specific meaning under one of those laws (for example "personal data", "personal information", "processing", "controller", "sensitive personal information"), we use it in that sense.

1. Who we are (controller and contact)

Pisama LLC is the controller of the personal data described in this policy. You can reach us about privacy using the contact form on this page. The Service operates at the callbackagent.ai and pisama.ai domains; the application backend is hosted in the United States.

For users in the EU/EEA or the UK, we have not yet appointed an Article 27 representative or a Data Protection Officer. Until one is named, send all data-protection requests using the contact form on this page.

2. The personal data we collect

We collect only what the Service needs to prepare and, where you direct it, help submit job applications.

3. Why we use your data, and our lawful basis

For users in the EU/EEA and the UK, we rely on the following Article 6 (and, for special-category data, Article 9) bases.

Under the CCPA/CPRA and other US state laws, we process the categories above for the business purposes described here. We do not use your sensitive personal information to infer characteristics about you, and we do not sell or "share" (as the CPRA defines "share", meaning cross-context behavioral advertising) your personal information. See Sections 5 and 8.

4. AI, automation, and automated decisions

The Service uses automated and AI systems, and you should understand how.

5. Who we share data with (processors and subprocessors)

We do not sell your data. We share personal data with the service providers ("processors" under the GDPR; "service providers" under the CCPA) that operate the Service, under contracts that restrict them to processing on our instructions. Our current providers are:

A current subprocessor list and the data-processing agreements with these providers are maintained for review (see Section 12). We require an Article 28 / CCPA service-provider agreement with each processor. We may also disclose data where required by law, to enforce our terms, or in connection with a corporate transaction, subject to this policy.

6. International data transfers

The Service is operated from the United States, and our AI and hosting providers process data in the United States and other countries. If you are in the EU/EEA or the UK, your personal data is transferred outside your home region. For those transfers we rely on appropriate safeguards under Chapter V of the GDPR and the UK regime, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and any applicable adequacy decision. You can contact us for more information about the safeguards that apply.

7. How long we keep data (retention)

We keep personal data only as long as we need it for the purposes above.

8. Your rights

Depending on where you live, you have some or all of the following rights, and we will not discriminate against you for exercising them.

9. Cookies, analytics, and consent

The Service uses a small number of strictly necessary cookies (for example to keep you signed in and to remember your theme choice); these are required for the site to work. It also uses non-essential analytics: privacy-focused product analytics and performance timings (Vercel Analytics and Speed Insights) and, where enabled, Google Analytics 4 aggregate measurement. These analytics see how pages are used, not the contents of your résumé, jobs, or answers.

Where consent is required for non-essential cookies and analytics (for example under EU/UK ePrivacy and PECR rules), we do not load them until you have given consent. Visitors we detect as being in a region that requires prior consent are not tracked by non-essential analytics unless and until they accept; everyone can change their choice. The current detection is best-effort.

10. How we protect your data

Résumé text, phone, location, and LinkedIn URL are encrypted at rest (AES-GCM), and rendered résumé PDFs are encrypted on disk. Your authentication token is held server-side and is never exposed to client-side JavaScript. We do not store your third-party portal or LinkedIn credentials. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security. Where the law requires it, we will notify you and the relevant authority of a personal-data breach within the applicable deadlines.

11. Children

The Service is intended for adults (18 and over) applying for jobs and is not directed to children. We do not knowingly collect personal data from children under 13 (or the minimum age set by local law). If you believe a child has provided us data, contact us using the form on this page and we will delete it.

12. Changes and how to contact us

We may update this policy. When we make a material change we will update the version and effective date above and, where appropriate, notify you. For any privacy question, to exercise a right, or to request our current subprocessor list or the safeguards that apply to international transfers, contact us using the form on this page. EU/EEA and UK users also have the right to complain to their supervisory authority (their national data protection authority, or the UK ICO).

Contact

Questions about your privacy, or want to make a data request? Send us a note and we will reply within a few business days.