PICOCEO OÜ ("PicoCEO", "we", "us"), a company registered in Estonia under company number 17544661, with its registered office at Ahtri tn 12, 15551 Tallinn, Estonia, operates the PicoCEO Cloud service at picoceo.com (the "Service").
For the personal data described here, PicoCEO is the data controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR.
This Policy explains how we handle personal data of account users, website visitors, and business contacts.
| Category | Examples | Source |
|---|---|---|
| Account data | Display name, email address, hashed password, company/workspace name, company ID, role/admin status | You, at sign-up |
| Billing data | Plan, credit balance and usage, billing events, invoices. Card / payment-instrument details are collected and stored by our Merchant of Record (Paddle), not by us — we receive only limited transaction metadata. | You / Paddle |
| Content & usage data | Directives you enter, tasks and artifacts your workspace generates, activity/system logs, knowledge-base files you upload, workspace and team configuration | You / your use |
| Integration data | Access tokens/credentials for channels you connect (e.g. Telegram bot token, email SMTP/IMAP credentials, OAuth tokens for Meta/Google/TikTok) and content exchanged over them | You, on connect |
| AI interaction data | Prompts, context and content sent to AI models, and the outputs returned | Your use |
| Device & technical data | IP address, browser/device type, approx. location from IP, mobile push token (Firebase Cloud Messaging), timestamps, diagnostic logs | Automatically |
| Communications | Emails/messages you send us (support, sales) | You |
| Local storage | A session token and small UI preferences in your browser's localStorage — see §11 | Your browser |
We do not intentionally collect special-category data (Art. 9 GDPR). Please do not upload such data unless you have a lawful basis; you remain the controller of content you upload.
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Create and administer your account; provide the Service | Contract (6(1)(b)) |
| Process AI directives, run your workspace, store and return outputs | Contract (6(1)(b)) |
| Take payments, meter credits, prevent billing fraud | Contract; Legal obligation (6(1)(c)); Legitimate interests (6(1)(f)) |
| Connect and operate third-party channels you enable | Contract (6(1)(b)) |
| Secure the Service, prevent abuse, keep audit logs | Legitimate interests (6(1)(f)) |
| Provide support | Contract / Legitimate interests |
| Improve/troubleshoot using aggregated or de-identified data | Legitimate interests (6(1)(f)) |
| Service/transactional emails | Contract / Legitimate interests |
| Marketing emails (if any) | Consent (6(1)(a)) where required; opt out anytime |
| Comply with legal obligations | Legal obligation (6(1)(c)) |
Where we rely on legitimate interests, we have balanced those against your rights; you may object at any time (see §10).
(a) Sub-processors processing on our behalf under Art. 28 contracts:
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Google Cloud (Google Ireland Ltd / Google LLC) | Hosting, compute (Cloud Run), database (Firestore), storage | EU — europe-west1 (Belgium); SCCs for any non-EEA support access |
| Google — Vertex AI / Gemini | AI model inference | [CONFIRM REGION — see note]; SCCs where applicable |
| Firebase Cloud Messaging (Google) | Mobile push notifications | Google infrastructure; SCCs where applicable |
| Paddle.com Market Limited | Merchant of Record: payments, invoicing, VAT/sales tax | UK/EU; UK adequacy + SCCs. Independent controller for payment/tax data. |
| [EMAIL / SUPPORT / ANALYTICS, if any] | [PURPOSE] | [LOCATION / SAFEGUARD] |
A current, itemised list is maintained in the GDPR & DPA → Annex II.
(b) Channels you connect. When you connect a third-party channel (e.g. Telegram, Meta, WhatsApp, Google, TikTok, Zalo, or an email account), data flows to and from that provider at your direction, under their own privacy policies.
(c) Professional advisers, auditors, and authorities where required by law, and acquirers in a corporate transaction (subject to confidentiality). We do not sell your personal data.
europe-west3 (Frankfurt) for AI inference — the actual AI region/provider must be confirmed and this table updated to match before publication.Your data is primarily stored and processed in the European Union. Where a sub-processor or support function processes data outside the EEA, we rely on an EU adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) with supplementary measures as needed. Request details for any specific transfer via §1.
| Data | Retention |
|---|---|
| Account data | Life of your account, then deleted/anonymised within [30–90 days] of closure |
| Content, artifacts, logs | While your workspace is active; deleted within [X days] of deletion/closure, subject to backups |
| Integration credentials | Until you disconnect the channel or close the account |
| Billing/tax records | As required by law (typically [6–10] years) |
| Backups | Rolling, overwritten within [X days] |
We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), access controls and least-privilege, secrets in a managed secret store (not in code), tenant data isolation, and audit logging. See GDPR & DPA → Annex III. No system is perfectly secure.
Subject to the GDPR, you have the right to access (Art. 15), rectify (16), erase (17), restrict (18), data portability (20), object (21), withdraw consent (7(3)), and not be subject to solely automated decisions (22).
To exercise any right, contact tuan@picoceo.com. We respond within one month (extendable by two for complex requests) and may need to verify your identity. You may also lodge a complaint with a supervisory authority; our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.
localStorage to keep you signed in and remember settings — essential, not used for tracking or advertising. Strictly necessary storage does not require consent.If you deploy any non-essential cookies, add a compliant consent banner and a cookie table here before launch. [CONFIRM]
The Service is not directed to children under [16] and we do not knowingly collect their data. Contact us and we will delete any such data.
We may update this Policy. Material changes will be notified by email or in-app. The "Last updated" date shows the current version.
PICOCEO OÜ — Ahtri tn 12, 15551 Tallinn, Estonia · Privacy / DPO: tuan@picoceo.com