Privacy Policy
Who we are & scope
Outsource is a marketing-services platform operated by The Good Picture, based in Nairobi, Kenya. For personal data processed at outsource.thegoodpicture.com, we act as the data controller for account and platform data, and as a processor for the client content you submit to have work done. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights.
Who operates this service
Outsource is operated by The Good Picture, based in Nairobi, Kenya.
Data-protection contact: contact@thegoodpicture.com. Privacy matters are handled by our team and escalated to our founders, Frédéric Cavé and Alexandre Brecher, where needed.
Personal data we collect
Depending on how you use the Service, we collect the following categories of personal data:
Category
Examples
Source
Account data
Name, email, role, company, authentication identifiers
You, at sign-up or when invited
Content you provide
Briefs, comments, files, brand assets, deliverables
You and your Members
Usage & device data
Pages viewed, actions taken, device & browser, IP, log data
Collected automatically as you use the Service
Billing data
Plan, add-ons, invoices, billing contact
You and our payment processor
Integration data
Encrypted OAuth tokens, basic profile of a connected account
The platform you connect, at your request
Support data
Messages and attachments you send us
You
We do not intentionally collect special-category data (such as health or political data) and ask that you not submit it.
How we use your data & our legal bases
Where the GDPR or the Kenya Data Protection Act, 2019 applies, we rely on the following legal bases. We use your data only for the purposes below.
Purpose
Legal basis
Provide, operate, and deliver the Service you signed up for
Performance of a contract
Produce, review, and — only when you initiate it — publish content on your behalf
Contract / your consent for optional integrations
Send transactional messages about your account, deliveries, and support
Contract / legitimate interests
Secure the platform, prevent abuse, and keep audit records
Legitimate interests
Measure aggregate traffic (cookieless analytics)
Legitimate interests
Comply with tax, accounting, and other legal obligations
Legal obligation
Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time (see your rights below). We do not sell your personal data.
AI & automated processing
Some features use AI, provided by our sub-processor Anthropic, to help draft, adapt, and summarise content. Content you send to these features is not used to train the underlying models.
We do not use your personal data to make decisions that produce legal or similarly significant effects about you solely by automated means. AI output is a draft for a human to review — a person is always in the loop before anything is delivered or published.
Cookies & analytics
We use only essential and functional first-party cookies and local storage (primarily to keep you signed in and remember interface preferences), plus Vercel Web Analytics, a privacy-friendly, cookieless tool that records anonymised page views. We do not use advertising or cross-site tracking cookies.
Full details, including a cookie-by-cookie table, are in our Cookie Policy.
6.Sub-processors
We rely on the vetted sub-processors below to operate the Service. Each is engaged under a data-processing agreement with appropriate safeguards.
Sub-processor
Purpose
Location
Primary database, authentication & file storage
European Union — Frankfurt (eu-central-1)
Application hosting, CDN & cookieless web analytics
United States / global edge network
AI content generation (Claude)
United States
Transactional email delivery
United States
Workflow automation & orchestration
European Union
Error monitoring & diagnostics
United States
Payment processing (subscriptions & invoices)
Nigeria / South Africa
Social publishing — only when you connect it
United States / European Union
Social publishing — only when you connect it
United States / European Union
The full list, with the data each one processes, is on our Sub-processors page, which you can subscribe to for change notifications.
Sharing & disclosure
We share personal data only:
With the sub-processors listed above, to operate the Service on our behalf;
With third-party platforms you choose to connect, for actions you initiate;
Where required by law, court order, or a lawful request by a public authority;
To protect our rights, safety, and property, or those of our users, where reasonably necessary;
In connection with a merger, acquisition, or sale of assets, under confidentiality and this policy.
We do not otherwise disclose your personal data, and we never sell it.
Where your data is stored & international transfers
Your account and content data is stored in our primary database (Supabase) in the European Union (Frankfurt). Workflow automation (n8n Cloud) also runs in the EU. Application hosting (Vercel) and some sub-processors (Anthropic, Postmark, Sentry) run in the United States; our payment processor (Paystack) operates in Nigeria and South Africa.
Where personal data of individuals in the EU/EEA, UK, or Kenya is transferred to a country without an adequacy decision, we rely on appropriate safeguards under GDPR Article 46 — principally Standard Contractual Clauses — together with each sub-processor’s own transfer mechanisms and, where relevant, supplementary measures such as encryption.
Data retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it.
Data
Retention period
Account data
Life of the account + 30 days
Content & deliveries
Life of the account + 90 days
Integration tokens
Until you disconnect the integration or the token expires
System logs
90 days
Audit & security logs
2 years
Billing & invoicing records
7 years (Kenyan tax law)
Backups
Aged out on our normal rotation, up to 90 days
Your rights
Subject to applicable law, you have rights over your personal data. To exercise any of them, email contact@thegoodpicture.com. We respond within 30 days and may ask you to verify your identity first.
Under the GDPR (EU/EEA/UK) and the Kenya Data Protection Act, 2019
Access — a copy of the personal data we hold about you.
Rectification — correct inaccurate or incomplete data.
Erasure — delete your data (the “right to be forgotten”).
Portability — receive your data in a structured, machine-readable format.
Restriction — limit how we process your data.
Objection — object to processing based on legitimate interests.
Withdraw consent — where we rely on consent, withdraw it at any time.
You may also lodge a complaint with your supervisory authority — in Kenya, the Office of the Data Protection Commissioner (ODPC); in the EU/EEA, your local authority.
If you are a California resident (CCPA/CPRA)
You have the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights.
Security
We protect your data with encryption in transit and at rest, row-level access controls, encrypted integration tokens, least-privilege access, and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and review our practices regularly. Our full posture is described on the Security page.
Children’s data
Outsource is a business tool intended for professional use. It is not directed to, and we do not knowingly collect personal data from, anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
Breach notification
In the event of a personal-data breach likely to result in a risk to your rights, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Articles 33 and 34 and the equivalent Kenyan requirements.
Data Processing Agreement
Business customers who need a Data Processing Agreement (DPA) — for example where we process personal data on your behalf as your processor — can request one at contact@thegoodpicture.com. Our DPA incorporates the Standard Contractual Clauses and our current sub-processor list.
Changes to this policy
We may update this policy from time to time. For material changes, we will give at least 30 days’ notice by email and update the version and effective date above before the changes take effect.
16 .Contact
For any privacy question, or to exercise a right, contact our data-protection contact at contact@thegoodpicture.com.