PICOCEO← Back to appTermsGDPR & DPA →

Privacy Policy — PicoCEO Cloud

Effective date: 3 August 2026  ·  Last updated: 3 August 2026

1. Who we are (the "data controller")

PICOCEO OÜ ("PicoCEO", "we", "us"), a company registered in Estonia under company number 17544661, with its registered office at Ahtri tn 12, 15551 Tallinn, Estonia, operates the PicoCEO Cloud service at picoceo.com (the "Service").

For the personal data described here, PicoCEO is the data controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR.

Our two roles. When you use PicoCEO to process other people's data — e.g. messages from your customers arriving through a connected support channel, or documents you upload to your knowledge base — you are the controller and we act as your processor. Those arrangements are governed by our GDPR & Data Processing Addendum, not this Policy. This Policy covers data for which we decide the purposes and means: your account, billing, and how you personally use the Service.

2. Scope

This Policy explains how we handle personal data of account users, website visitors, and business contacts.

3. The personal data we collect

CategoryExamplesSource
Account dataDisplay name, email address, hashed password, company/workspace name, company ID, role/admin statusYou, at sign-up
Billing dataPlan, credit balance and usage, billing events, invoices. Card / payment-instrument details are collected and stored by our Merchant of Record (Paddle), not by us — we receive only limited transaction metadata.You / Paddle
Content & usage dataDirectives you enter, tasks and artifacts your workspace generates, activity/system logs, knowledge-base files you upload, workspace and team configurationYou / your use
Integration dataAccess tokens/credentials for channels you connect (e.g. Telegram bot token, email SMTP/IMAP credentials, OAuth tokens for Meta/Google/TikTok) and content exchanged over themYou, on connect
AI interaction dataPrompts, context and content sent to AI models, and the outputs returnedYour use
Device & technical dataIP address, browser/device type, approx. location from IP, mobile push token (Firebase Cloud Messaging), timestamps, diagnostic logsAutomatically
CommunicationsEmails/messages you send us (support, sales)You
Local storageA session token and small UI preferences in your browser's localStorage — see §11Your browser

We do not intentionally collect special-category data (Art. 9 GDPR). Please do not upload such data unless you have a lawful basis; you remain the controller of content you upload.

4. Why we use your data, and our legal bases

PurposeLegal basis (Art. 6 GDPR)
Create and administer your account; provide the ServiceContract (6(1)(b))
Process AI directives, run your workspace, store and return outputsContract (6(1)(b))
Take payments, meter credits, prevent billing fraudContract; Legal obligation (6(1)(c)); Legitimate interests (6(1)(f))
Connect and operate third-party channels you enableContract (6(1)(b))
Secure the Service, prevent abuse, keep audit logsLegitimate interests (6(1)(f))
Provide supportContract / Legitimate interests
Improve/troubleshoot using aggregated or de-identified dataLegitimate interests (6(1)(f))
Service/transactional emailsContract / Legitimate interests
Marketing emails (if any)Consent (6(1)(a)) where required; opt out anytime
Comply with legal obligationsLegal obligation (6(1)(c))

Where we rely on legitimate interests, we have balanced those against your rights; you may object at any time (see §10).

5. AI processing

6. Who we share data with

(a) Sub-processors processing on our behalf under Art. 28 contracts:

Sub-processorPurposeLocation / safeguard
Google Cloud (Google Ireland Ltd / Google LLC)Hosting, compute (Cloud Run), database (Firestore), storageEU — europe-west1 (Belgium); SCCs for any non-EEA support access
Google — Vertex AI / GeminiAI model inference[CONFIRM REGION — see note]; SCCs where applicable
Firebase Cloud Messaging (Google)Mobile push notificationsGoogle infrastructure; SCCs where applicable
Paddle.com Market LimitedMerchant of Record: payments, invoicing, VAT/sales taxUK/EU; UK adequacy + SCCs. Independent controller for payment/tax data.
[EMAIL / SUPPORT / ANALYTICS, if any][PURPOSE][LOCATION / SAFEGUARD]

A current, itemised list is maintained in the GDPR & DPA → Annex II.

(b) Channels you connect. When you connect a third-party channel (e.g. Telegram, Meta, WhatsApp, Google, TikTok, Zalo, or an email account), data flows to and from that provider at your direction, under their own privacy policies.

(c) Professional advisers, auditors, and authorities where required by law, and acquirers in a corporate transaction (subject to confidentiality). We do not sell your personal data.

Data-residency note. Our infrastructure runs in Google Cloud europe-west1 (Belgium). Some public materials reference europe-west3 (Frankfurt) for AI inference — the actual AI region/provider must be confirmed and this table updated to match before publication.

7. International transfers

Your data is primarily stored and processed in the European Union. Where a sub-processor or support function processes data outside the EEA, we rely on an EU adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) with supplementary measures as needed. Request details for any specific transfer via §1.

8. How long we keep data

DataRetention
Account dataLife of your account, then deleted/anonymised within [30–90 days] of closure
Content, artifacts, logsWhile your workspace is active; deleted within [X days] of deletion/closure, subject to backups
Integration credentialsUntil you disconnect the channel or close the account
Billing/tax recordsAs required by law (typically [6–10] years)
BackupsRolling, overwritten within [X days]

9. How we protect data

We apply technical and organisational measures appropriate to the risk: encryption in transit (TLS), access controls and least-privilege, secrets in a managed secret store (not in code), tenant data isolation, and audit logging. See GDPR & DPA → Annex III. No system is perfectly secure.

10. Your rights

Subject to the GDPR, you have the right to access (Art. 15), rectify (16), erase (17), restrict (18), data portability (20), object (21), withdraw consent (7(3)), and not be subject to solely automated decisions (22).

To exercise any right, contact tuan@picoceo.com. We respond within one month (extendable by two for complex requests) and may need to verify your identity. You may also lodge a complaint with a supervisory authority; our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.

11. Cookies and local storage

If you deploy any non-essential cookies, add a compliant consent banner and a cookie table here before launch. [CONFIRM]

12. Children

The Service is not directed to children under [16] and we do not knowingly collect their data. Contact us and we will delete any such data.

13. Changes to this Policy

We may update this Policy. Material changes will be notified by email or in-app. The "Last updated" date shows the current version.

14. Contact

PICOCEO OÜ — Ahtri tn 12, 15551 Tallinn, Estonia · Privacy / DPO: tuan@picoceo.com