PICOCEO← Back to appTermsPrivacy Policy →

GDPR Compliance & Data Processing Addendum (DPA)

Effective date: 3 August 2026  ·  Version: [1.0]

This Data Processing Addendum ("DPA") forms part of the agreement between PICOCEO OÜ ("PicoCEO") and the customer ("Customer", "you") for use of the PicoCEO Cloud service (the "Service"). It governs processing of personal data that PicoCEO carries out on the Customer's behalf under the EU GDPR and, where applicable, the UK GDPR.

1. Roles of the parties

2. Processing instructions

PicoCEO processes Customer Personal Data only on the Customer's documented instructions (including the agreement, this DPA, and the Customer's configuration/use), unless required by EU/Member-State law (in which case PicoCEO informs the Customer unless legally prohibited). PicoCEO will inform the Customer if, in its opinion, an instruction infringes the GDPR.

3. Subject-matter and details of processing

The nature, purpose, duration, types of data and categories of data subjects are set out in Annex I.

4. Confidentiality

PicoCEO ensures persons authorised to process Customer Personal Data are bound by confidentiality and process it only as instructed.

5. Security (Art. 32)

PicoCEO implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex III.

6. Assistance to the Customer

Taking into account the nature of processing, PicoCEO will assist the Customer, insofar as possible, to respond to data-subject requests (Art. 12–23) and to meet obligations under Art. 32–36 (security, breach notification, DPIAs, prior consultation). The Service provides self-service tools (export and deletion of workspace data, disconnecting channels) to fulfil many such requests directly.

7. Sub-processors

8. International transfers

Customer Personal Data is hosted in the EU (europe-west1, Belgium). Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or the EU Standard Contractual Clauses (SCCs, 2021/914) (appropriate Module) with supplementary measures where required. The SCCs are incorporated by reference where transfers occur.

9. Personal-data breaches

PicoCEO will notify the Customer without undue delay (and, where feasible, within [72] hours) after becoming aware of a personal-data breach affecting Customer Personal Data, providing information reasonably required for the Customer's Art. 33/34 obligations.

10. Deletion or return

On termination or expiry, PicoCEO will, at the Customer's choice, delete or return Customer Personal Data within [X days] and delete existing copies unless EU/Member-State law requires storage. Backups are purged on the rolling cycle in Annex III.

11. Audits

PicoCEO will make available information necessary to demonstrate Art. 28 compliance and allow for and contribute to audits — subject to reasonable notice, confidentiality, and frequency limits ([e.g. once per 12 months unless a breach or regulator requires more]). PicoCEO may satisfy audit requests with third-party certifications/reports where available.

12. Liability & precedence

Liability is subject to the limitations in the agreement. On data-protection conflicts, this DPA prevails over the rest of the agreement.

Annex I — Details of processing

ItemDetail
Subject-matterProvision of the PicoCEO Cloud AI-workspace service
DurationTerm of the agreement, plus the deletion/return period
Nature & purposeHosting, storing and computing on Customer content; sending content to AI models to generate outputs; operating connected channels on the Customer's behalf; metering usage
Types of personal dataIdentifiers and contact details; message/communication content; uploaded documents and their contents; integration account identifiers and credentials; and any personal data the Customer includes in directives, knowledge-base files, or channel messages
Special categoriesNot intended. The Customer must not submit Art. 9 data unless it has a lawful basis and has assessed the risk; the Customer remains responsible for content it submits
Categories of data subjectsThe Customer's staff/users; the Customer's own customers/contacts who communicate through connected channels; third parties referenced in the Customer's content
FrequencyContinuous, for the duration of use

Annex II — Sub-processors

Kept in sync with Privacy Policy §6. Confirm each entity's exact legal name and location before publication.

#Sub-processor (legal entity)ServiceLocationTransfer safeguard
1Google Cloud — [Google Ireland Ltd / Google LLC]Hosting, compute (Cloud Run), database (Firestore), storageEU — europe-west1 (Belgium)Intra-EEA; SCCs for any non-EEA support access
2Google — Vertex AI / GeminiAI model inference[CONFIRM REGION]SCCs where applicable
3Google — Firebase Cloud MessagingMobile push notificationsGoogle infrastructureSCCs where applicable
4Paddle.com Market LimitedMerchant of Record — payments, invoicing, VAT/sales tax[UK / EU]UK adequacy + SCCs; independent controller for payment/tax data
5[Transactional email provider, if any][Service emails][LOCATION][SAFEGUARD]
6[Error-monitoring / analytics, if any][Diagnostics][LOCATION][SAFEGUARD]
Channels connected by the Customer (Telegram, Meta, WhatsApp, Google, TikTok, Zalo, email hosts, etc.) are not PicoCEO sub-processors — they process data under the Customer's own relationship with those providers, at the Customer's direction.

Annex III — Technical & organisational measures (TOMs)

Reflecting the current architecture; confirm and expand before publication.