1. Purpose
This document defines BACCA.AI’s policies for LLM data tenancy, data residency, and data retention. It establishes how data is isolated per customer, where LLM-related data may be processed and stored, and how long such data is retained or deleted. The objective is to ensure strong security guarantees, regulatory compliance, and customer trust while leveraging Large Language Models (LLMs) within the BACCA.AI AI SRE platform.
This policy defines how data is handled, isolated, processed, stored, and protected when using Large Language Models (LLMs) within the BACCA.AI AI SRE product. The goal is to ensure strong tenant isolation, data confidentiality, regulatory compliance, and customer trust while leveraging LLM capabilities.
2. Scope
This policy applies to:
- All BACCA.AI environments (production, staging, development)
- All customer (tenant) data processed by LLM-powered features
- All LLM-related data flows including prompts, context, embeddings, outputs, logs, and metadata
- All internal teams and approved third-party LLM providers
This policy applies to:
- All BACCA.AI production, staging, and development environments
- All customer (tenant) data processed by LLM-powered features
- All internal users, systems, services, and third-party providers involved in LLM usage
3. Definitions
- Tenant: A BACCA.AI customer or logically isolated customer environment
- Tenant Data: Any data provided by or derived from a tenant, including logs, metrics, traces, alerts, configuration, prompts, and outputs
- LLM Provider: Any internal or third-party system that provides large language model inference or training services
- Prompt: Input text or structured data sent to an LLM