Privacy Policy

  1. Who we are & scope

    Outsource is a marketing-services platform operated by The Good Picture, based in Nairobi, Kenya. For personal data processed at outsource.thegoodpicture.com, we act as the data controller for account and platform data, and as a processor for the client content you submit to have work done. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights.

    Who operates this service

    Outsource is operated by The Good Picture, based in Nairobi, Kenya.

    Data-protection contact: contact@thegoodpicture.com. Privacy matters are handled by our team and escalated to our founders, Frédéric Cavé and Alexandre Brecher, where needed.

    1. Personal data we collect

    Depending on how you use the Service, we collect the following categories of personal data:


    Category

    Examples

    Source

    Account data

    Name, email, role, company, authentication identifiers

    You, at sign-up or when invited

    Content you provide

    Briefs, comments, files, brand assets, deliverables

    You and your Members

    Usage & device data

    Pages viewed, actions taken, device & browser, IP, log data

    Collected automatically as you use the Service

    Billing data

    Plan, add-ons, invoices, billing contact

    You and our payment processor

    Integration data

    Encrypted OAuth tokens, basic profile of a connected account

    The platform you connect, at your request

    Support data

    Messages and attachments you send us

    You

    We do not intentionally collect special-category data (such as health or political data) and ask that you not submit it.

    1. How we use your data & our legal bases

    Where the GDPR or the Kenya Data Protection Act, 2019 applies, we rely on the following legal bases. We use your data only for the purposes below.


    Purpose

    Legal basis

    Provide, operate, and deliver the Service you signed up for

    Performance of a contract

    Produce, review, and — only when you initiate it — publish content on your behalf

    Contract / your consent for optional integrations

    Send transactional messages about your account, deliveries, and support

    Contract / legitimate interests

    Secure the platform, prevent abuse, and keep audit records

    Legitimate interests

    Measure aggregate traffic (cookieless analytics)

    Legitimate interests

    Comply with tax, accounting, and other legal obligations

    Legal obligation

    Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time (see your rights below). We do not sell your personal data.

    1. AI & automated processing

    Some features use AI, provided by our sub-processor Anthropic, to help draft, adapt, and summarise content. Content you send to these features is not used to train the underlying models.

    We do not use your personal data to make decisions that produce legal or similarly significant effects about you solely by automated means. AI output is a draft for a human to review — a person is always in the loop before anything is delivered or published.

    1. Cookies & analytics

    We use only essential and functional first-party cookies and local storage (primarily to keep you signed in and remember interface preferences), plus Vercel Web Analytics, a privacy-friendly, cookieless tool that records anonymised page views. We do not use advertising or cross-site tracking cookies.

    Full details, including a cookie-by-cookie table, are in our Cookie Policy.

    6.Sub-processors

    We rely on the vetted sub-processors below to operate the Service. Each is engaged under a data-processing agreement with appropriate safeguards.


    Sub-processor

    Purpose

    Location

    Supabase

    Primary database, authentication & file storage

    European Union — Frankfurt (eu-central-1)

    Vercel

    Application hosting, CDN & cookieless web analytics

    United States / global edge network

    Anthropic

    AI content generation (Claude)

    United States

    Postmark

    Transactional email delivery

    United States

    n8n Cloud

    Workflow automation & orchestration

    European Union

    Sentry

    Error monitoring & diagnostics

    United States

    Paystack

    Payment processing (subscriptions & invoices)

    Nigeria / South Africa

    LinkedIn

    Social publishing — only when you connect it

    United States / European Union

    Meta

    Social publishing — only when you connect it

    United States / European Union

    The full list, with the data each one processes, is on our Sub-processors page, which you can subscribe to for change notifications.

    1. Sharing & disclosure

    We share personal data only:

    • With the sub-processors listed above, to operate the Service on our behalf;

    • With third-party platforms you choose to connect, for actions you initiate;

    • Where required by law, court order, or a lawful request by a public authority;

    • To protect our rights, safety, and property, or those of our users, where reasonably necessary;

    • In connection with a merger, acquisition, or sale of assets, under confidentiality and this policy.

    We do not otherwise disclose your personal data, and we never sell it.

    1. Where your data is stored & international transfers

    Your account and content data is stored in our primary database (Supabase) in the European Union (Frankfurt). Workflow automation (n8n Cloud) also runs in the EU. Application hosting (Vercel) and some sub-processors (Anthropic, Postmark, Sentry) run in the United States; our payment processor (Paystack) operates in Nigeria and South Africa.

    Where personal data of individuals in the EU/EEA, UK, or Kenya is transferred to a country without an adequacy decision, we rely on appropriate safeguards under GDPR Article 46 — principally Standard Contractual Clauses — together with each sub-processor’s own transfer mechanisms and, where relevant, supplementary measures such as encryption.

    1. Data retention

    We keep personal data only as long as needed for the purposes above, then delete or anonymise it.

    Data

    Retention period

    Account data

    Life of the account + 30 days

    Content & deliveries

    Life of the account + 90 days

    Integration tokens

    Until you disconnect the integration or the token expires

    System logs

    90 days

    Audit & security logs

    2 years

    Billing & invoicing records

    7 years (Kenyan tax law)

    Backups

    Aged out on our normal rotation, up to 90 days

    1. Your rights

    Subject to applicable law, you have rights over your personal data. To exercise any of them, email contact@thegoodpicture.com. We respond within 30 days and may ask you to verify your identity first.

    Under the GDPR (EU/EEA/UK) and the Kenya Data Protection Act, 2019

    • Access — a copy of the personal data we hold about you.

    • Rectification — correct inaccurate or incomplete data.

    • Erasure — delete your data (the “right to be forgotten”).

    • Portability — receive your data in a structured, machine-readable format.

    • Restriction — limit how we process your data.

    • Objection — object to processing based on legitimate interests.

    • Withdraw consent — where we rely on consent, withdraw it at any time.

    You may also lodge a complaint with your supervisory authority — in Kenya, the Office of the Data Protection Commissioner (ODPC); in the EU/EEA, your local authority.

    If you are a California resident (CCPA/CPRA)

    You have the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights.

    1. Security

    We protect your data with encryption in transit and at rest, row-level access controls, encrypted integration tokens, least-privilege access, and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and review our practices regularly. Our full posture is described on the Security page.

    1. Children’s data

    Outsource is a business tool intended for professional use. It is not directed to, and we do not knowingly collect personal data from, anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

    1. Breach notification

    In the event of a personal-data breach likely to result in a risk to your rights, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Articles 33 and 34 and the equivalent Kenyan requirements.

    1. Data Processing Agreement

    Business customers who need a Data Processing Agreement (DPA) — for example where we process personal data on your behalf as your processor — can request one at contact@thegoodpicture.com. Our DPA incorporates the Standard Contractual Clauses and our current sub-processor list.

    1. Changes to this policy

    We may update this policy from time to time. For material changes, we will give at least 30 days’ notice by email and update the version and effective date above before the changes take effect.

    16 .Contact

    For any privacy question, or to exercise a right, contact our data-protection contact at contact@thegoodpicture.com.