1. Introduction and scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Picnic Technologies Ltd (company number 17283444, registered office: Techspace C/O Antler C/O Picnic, 140 Goswell Rd, London, EC1V 7DY, United Kingdom) ("Picnic") and the customer that accepts those Terms ("Customer"). It applies automatically, to every Customer and on every plan, wherever Picnic processes Customer Personal Data on the Customer's behalf.
For that processing, the Customer is the controller and Picnic is the processor within the meaning of the Data Protection Laws. Where Picnic acts as a controller in its own right — for account data, analytics, and its website — the Privacy Policy governs instead, and that processing is outside the scope of this DPA.
If there is a conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA prevails. Customers who need a countersigned or bespoke data processing agreement can contact legal@joinpicnic.com.
2. Definitions
- "Data Protection Laws" means the UK GDPR and the Data Protection Act 2018 and, where applicable to the Customer, the EU GDPR, in each case as amended from time to time.
- "Customer Personal Data" means personal data contained in content that the Customer or its users upload to, create in, or connect to the Service — including content ingested from connected sources — that Picnic processes on the Customer's behalf.
- "Sub-processor" means a third party engaged by Picnic to process Customer Personal Data.
- Terms such as "controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the Data Protection Laws. Capitalised terms not defined here have the meanings given in the Terms.
3. Details of the processing
- Subject matter and duration. The processing of Customer Personal Data to provide the Service, for the duration of the Terms plus the deletion period described in "Deletion and return".
- Nature and purpose. Hosting, storage, indexing (including full-text search indexes and vector embeddings), transmission to AI model providers for inference, generation of derived items (todos, opportunities, summaries, evidence excerpts), display to authorised workspace members, notification delivery, and backup — in each case solely to provide, secure, and support the Service.
- Categories of data subjects. The Customer's users; the Customer's employees, contractors, and other personnel who appear in connected sources; and third parties who appear in connected sources, such as meeting attendees, email correspondents, support-conversation participants, and the Customer's own customers.
- Categories of personal data. Names, email addresses, and identifiers; message and email content; documents and files; meeting notes and transcripts; issue and project data; support conversations; and billing and revenue records from the Customer's connected Stripe account. The Customer controls which sources are connected and therefore which categories are processed. The Service is not intended for special-category data, and the Customer agrees not to connect sources whose primary content is special-category data.
4. Processing on documented instructions
Picnic will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to Picnic — in which case Picnic will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
The Terms, this DPA, and the Customer's configuration of the Service (including which sources are connected, which integrations are enabled, and workspace permission settings) constitute the Customer's complete documented instructions. Picnic will inform the Customer if, in its opinion, an instruction infringes the Data Protection Laws.
The Customer further instructs and authorises Picnic to create aggregated and/or de-identified data — data that no longer identifies any individual or the Customer — from Customer Personal Data, and to use it to improve the Service as described in the Terms and the Privacy Policy, subject to the source exclusions stated there.
5. Confidentiality of personnel
Picnic ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to those who need it to provide, secure, or support the Service.
6. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, Picnic implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 UK GDPR. The current measures are described in "Technical and organisational measures" below. Picnic may update them from time to time, provided the updates do not materially reduce the overall level of protection.
7. Sub-processors
The Customer gives Picnic general written authorisation to engage Sub-processors to provide the Service. Picnic's current Sub-processors are listed in the sub-processor section of the Privacy Policy.
Picnic will:
- give the Customer reasonable prior notice before a new Sub-processor processes Customer Personal Data, by updating that list and, for material changes, by notice through the Service or by email;
- allow the Customer to object to the change on reasonable data protection grounds within 30 days of the notice — if the objection cannot be resolved, the Customer may terminate the affected part of the Service;
- impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, including the no-training commitment for AI model providers described in the Privacy Policy; and
- remain fully liable to the Customer for the performance of each Sub-processor's obligations.
8. Assistance with data subject rights
Taking into account the nature of the processing, Picnic will assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to data subjects' requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). If a data subject contacts Picnic directly about Customer Personal Data, Picnic will direct them to the Customer without undue delay and will not respond substantively except on the Customer's instruction or where required by law.
9. Personal data breach notification
Picnic will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects, and Picnic will provide reasonable further information as it becomes available. Picnic's notification is not an admission of fault or liability.
10. Assistance with impact assessments
Taking into account the nature of the processing and the information available to it, Picnic will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, in each case as required by Articles 35 and 36 UK GDPR and to the extent they relate to the processing of Customer Personal Data under this DPA.
11. Deletion and return
During the term, the Customer can delete content through the Service and can disconnect sources at any time, and may request deletion of previously ingested content by contacting legal@joinpicnic.com.
On termination of the Terms, or on the Customer's verified request, Picnic will — at the Customer's choice — return Customer Personal Data in a structured, commonly used, machine-readable format and/or delete it, within 30 days, and delete existing copies unless and to the extent that law requires or permits continued storage (for example for tax, audit, or fraud-prevention purposes). Residual copies in encrypted backups are deleted on a rolling schedule thereafter and are not restored to live systems except for disaster recovery.
12. Audits and information
Picnic will make available to the Customer the information reasonably necessary to demonstrate compliance with its obligations under Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
The parties agree that audits will in the first instance be satisfied by Picnic providing documentation, security summaries, and written responses to reasonable questions. Any on-site or remote inspection: requires at least 30 days' written notice; may occur at most once in any 12-month period (except following a personal data breach or where required by a supervisory authority); must be conducted during business hours without unreasonable disruption; is subject to confidentiality; and must not give access to other customers' data. Each party bears its own costs.
13. International transfers
Picnic will not transfer Customer Personal Data outside the UK or EEA unless the transfer is covered by an adequacy decision (including the UK–US Data Bridge for certified recipients), or made subject to appropriate safeguards under the Data Protection Laws — the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, as applicable — including for onward transfers to Sub-processors. The Customer can request details of the safeguards in place for a specific transfer by contacting legal@joinpicnic.com.
14. Liability and general
Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms, except to the extent that liability cannot lawfully be limited under the Data Protection Laws.
This DPA takes effect when the Customer accepts the Terms, continues for as long as Picnic processes Customer Personal Data, and is governed by the law of England and Wales, with the courts of England and Wales having exclusive jurisdiction. We may update this DPA from time to time in accordance with the change process in the Terms; material changes will be notified in advance.
15. Technical and organisational measures
Picnic currently implements the following measures for Customer Personal Data:
- Encryption. TLS for all data in transit; encryption at rest across databases, file storage, and backups; customer-supplied AI provider keys sealed with envelope encryption (AES-256-GCM).
- Credential isolation. OAuth tokens for connected sources are held in a dedicated token vault (operated by our Sub-processor Nango), never in Picnic's application database, and are revoked and deleted on disconnect.
- Access control. Workspace-scoped tenancy; permission-aware retrieval that mirrors source-system access (Google Drive sharing permissions, Slack channel and DM membership, document read gates); role-based administration; uploaded files served only through short-lived signed URLs from a private bucket.
- Data minimisation and retention. Slack and Gmail message bodies are automatically deleted 90 days after ingestion by scheduled jobs; content sent to AI providers is scoped to the task at hand; ingested identity data is stored using hashed identity keys where plaintext is not required.
- Operational security. Least-privilege access for Picnic personnel; append-only audit logs of sensitive actions; daily automated checks that enforce internal data-handling invariants; error tracking and infrastructure hosted in the UK/EU where noted in the Privacy Policy.
- Resilience. Managed, replicated database and storage infrastructure with encrypted backups; durable background-job orchestration with retries for ingestion and deletion pipelines.
16. Contact
Questions about this DPA, sub-processor notices, or requests for a countersigned or bespoke agreement:
Picnic Technologies LtdCompany number 17283444, registered in England and Wales
Registered office: Techspace C/O Antler C/O Picnic, 140 Goswell Rd, London, EC1V 7DY, United Kingdom
legal@joinpicnic.com