This Data Processing Addendum ("DPA") forms part of the agreement between PICOCEO OÜ ("PicoCEO") and the customer ("Customer", "you") for use of the PicoCEO Cloud service (the "Service"). It governs processing of personal data that PicoCEO carries out on the Customer's behalf under the EU GDPR and, where applicable, the UK GDPR.
PicoCEO processes Customer Personal Data only on the Customer's documented instructions (including the agreement, this DPA, and the Customer's configuration/use), unless required by EU/Member-State law (in which case PicoCEO informs the Customer unless legally prohibited). PicoCEO will inform the Customer if, in its opinion, an instruction infringes the GDPR.
The nature, purpose, duration, types of data and categories of data subjects are set out in Annex I.
PicoCEO ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as instructed.
PicoCEO implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex III.
Taking into account the nature of processing, PicoCEO will assist the Customer, insofar as possible, to respond to data-subject requests (Art. 12–23) and to meet obligations under Art. 32–36 (security, breach notification, DPIAs, prior consultation). The Service provides self-service tools (export and deletion of workspace data, disconnecting channels) to fulfil many such requests directly.
Customer Personal Data is hosted in the EU (europe-west1, Belgium). Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or the EU Standard Contractual Clauses (SCCs, 2021/914) (appropriate Module) with supplementary measures where required. The SCCs are incorporated by reference where transfers occur.
PicoCEO will notify the Customer without undue delay (and, where feasible, within [72] hours) after becoming aware of a personal-data breach affecting Customer Personal Data, providing information reasonably required for the Customer's Art. 33/34 obligations.
On termination or expiry, PicoCEO will, at the Customer's choice, delete or return Customer Personal Data within [X days] and delete existing copies unless EU/Member-State law requires storage. Backups are purged on the rolling cycle in Annex III.
PicoCEO will make available information necessary to demonstrate Art. 28 compliance and allow for and contribute to audits — subject to reasonable notice, confidentiality, and frequency limits ([e.g. once per 12 months unless a breach or regulator requires more]). PicoCEO may satisfy audit requests with third-party certifications/reports where available.
Liability is subject to the limitations in the agreement. On data-protection conflicts, this DPA prevails over the rest of the agreement.
| Item | Detail |
|---|---|
| Subject-matter | Provision of the PicoCEO Cloud AI-workspace service |
| Duration | Term of the agreement, plus the deletion/return period |
| Nature & purpose | Hosting, storing and computing on Customer content; sending content to AI models to generate outputs; operating connected channels on the Customer's behalf; metering usage |
| Types of personal data | Identifiers and contact details; message/communication content; uploaded documents and their contents; integration account identifiers and credentials; and any personal data the Customer includes in directives, knowledge-base files, or channel messages |
| Special categories | Not intended. The Customer must not submit Art. 9 data unless it has a lawful basis and has assessed the risk; the Customer remains responsible for content it submits |
| Categories of data subjects | The Customer's staff/users; the Customer's own customers/contacts who communicate through connected channels; third parties referenced in the Customer's content |
| Frequency | Continuous, for the duration of use |
| # | Sub-processor (legal entity) | Service | Location | Transfer safeguard |
|---|---|---|---|---|
| 1 | Google Cloud — [Google Ireland Ltd / Google LLC] | Hosting, compute (Cloud Run), database (Firestore), storage | EU — europe-west1 (Belgium) | Intra-EEA; SCCs for any non-EEA support access |
| 2 | Google — Vertex AI / Gemini | AI model inference | [CONFIRM REGION] | SCCs where applicable |
| 3 | Google — Firebase Cloud Messaging | Mobile push notifications | Google infrastructure | SCCs where applicable |
| 4 | Paddle.com Market Limited | Merchant of Record — payments, invoicing, VAT/sales tax | [UK / EU] | UK adequacy + SCCs; independent controller for payment/tax data |
| 5 | [Transactional email provider, if any] | [Service emails] | [LOCATION] | [SAFEGUARD] |
| 6 | [Error-monitoring / analytics, if any] | [Diagnostics] | [LOCATION] | [SAFEGUARD] |