Outsource by The Good Picture

Legal

Privacy Policy

How The Good Picture collects, uses, protects, and shares your data — and the rights you have over it.

Version 2.0Last updated 1 August 2026Effective 1 August 2026
On this page
  1. 1.Who we are & scope
  2. 2.Personal data we collect
  3. 3.How we use your data & our legal bases
  4. 4.AI & automated processing
  5. 5.Cookies & analytics
  6. 6.Sub-processors
  7. 7.Sharing & disclosure
  8. 8.Where your data is stored & international transfers
  9. 9.Data retention
  10. 10.Your rights
  11. 11.Security
  12. 12.Children’s data
  13. 13.Breach notification
  14. 14.Data Processing Agreement
  15. 15.Changes to this policy
  16. 16.Contact

1.Who we are & scope

Outsource is a marketing-services platform operated by The Good Picture, based in Nairobi, Kenya. For personal data processed at outsource.thegoodpicture.com, we act as the data controller for account and platform data, and as a processor for the client content you submit to have work done. This policy explains what we collect, why, who we share it with, how long we keep it, and your rights.

Who operates this service

Outsource is operated by The Good Picture, based in Nairobi, Kenya.

Data-protection contact: contact@thegoodpicture.com. Privacy matters are handled by our team and escalated to our founders, Frédéric Cavé and Alexandre Brecher, where needed.

2.Personal data we collect

Depending on how you use the Service, we collect the following categories of personal data:

CategoryExamplesSource
Account dataName, email, role, company, authentication identifiersYou, at sign-up or when invited
Content you provideBriefs, comments, files, brand assets, deliverablesYou and your Members
Usage & device dataPages viewed, actions taken, device & browser, IP, log dataCollected automatically as you use the Service
Billing dataPlan, add-ons, invoices, billing contactYou and our payment processor
Integration dataEncrypted OAuth tokens, basic profile of a connected accountThe platform you connect, at your request
Support dataMessages and attachments you send usYou

We do not intentionally collect special-category data (such as health or political data) and ask that you not submit it.

3.How we use your data & our legal bases

Where the GDPR or the Kenya Data Protection Act, 2019 applies, we rely on the following legal bases. We use your data only for the purposes below.

PurposeLegal basis
Provide, operate, and deliver the Service you signed up forPerformance of a contract
Produce, review, and — only when you initiate it — publish content on your behalfContract / your consent for optional integrations
Send transactional messages about your account, deliveries, and supportContract / legitimate interests
Secure the platform, prevent abuse, and keep audit recordsLegitimate interests
Measure aggregate traffic (cookieless analytics)Legitimate interests
Comply with tax, accounting, and other legal obligationsLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time (see your rights below). We do not sell your personal data.

4.AI & automated processing

Some features use AI, provided by our sub-processor Anthropic, to help draft, adapt, and summarise content. Content you send to these features is not used to train the underlying models.

We do not use your personal data to make decisions that produce legal or similarly significant effects about you solely by automated means. AI output is a draft for a human to review — a person is always in the loop before anything is delivered or published.

5.Cookies & analytics

We use only essential and functional first-party cookies and local storage (primarily to keep you signed in and remember interface preferences), plus Vercel Web Analytics, a privacy-friendly, cookieless tool that records anonymised page views. We do not use advertising or cross-site tracking cookies.

Full details, including a cookie-by-cookie table, are in our Cookie Policy.

6.Sub-processors

We rely on the vetted sub-processors below to operate the Service. Each is engaged under a data-processing agreement with appropriate safeguards.

Sub-processorPurposeLocation
SupabasePrimary database, authentication & file storageEuropean Union — Frankfurt (eu-central-1)
VercelApplication hosting, CDN & cookieless web analyticsUnited States / global edge network
AnthropicAI content generation (Claude)United States
PostmarkTransactional email deliveryUnited States
n8n CloudWorkflow automation & orchestrationEuropean Union
SentryError monitoring & diagnosticsUnited States
PaystackPayment processing (subscriptions & invoices)Nigeria / South Africa
LinkedInSocial publishing — only when you connect itUnited States / European Union
MetaSocial publishing — only when you connect itUnited States / European Union

The full list, with the data each one processes, is on our Sub-processors page, which you can subscribe to for change notifications.

7.Sharing & disclosure

We share personal data only:

  • With the sub-processors listed above, to operate the Service on our behalf;
  • With third-party platforms you choose to connect, for actions you initiate;
  • Where required by law, court order, or a lawful request by a public authority;
  • To protect our rights, safety, and property, or those of our users, where reasonably necessary;
  • In connection with a merger, acquisition, or sale of assets, under confidentiality and this policy.

We do not otherwise disclose your personal data, and we never sell it.

8.Where your data is stored & international transfers

Your account and content data is stored in our primary database (Supabase) in the European Union (Frankfurt). Workflow automation (n8n Cloud) also runs in the EU. Application hosting (Vercel) and some sub-processors (Anthropic, Postmark, Sentry) run in the United States; our payment processor (Paystack) operates in Nigeria and South Africa.

Where personal data of individuals in the EU/EEA, UK, or Kenya is transferred to a country without an adequacy decision, we rely on appropriate safeguards under GDPR Article 46 — principally Standard Contractual Clauses — together with each sub-processor’s own transfer mechanisms and, where relevant, supplementary measures such as encryption.

9.Data retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it.

DataRetention period
Account dataLife of the account + 30 days
Content & deliveriesLife of the account + 90 days
AI generation recordsLife of the account + 90 days — kept with the work they produced
Integration tokensUntil you disconnect the integration or the token expires
System logs (heartbeats, page beacons)90 days
AI usage & cost records, email delivery records24 months
Audit & security logs2 years
Billing & invoicing records7 years (Kenyan tax law)
BackupsAged out on our normal rotation, up to 90 days

10.Your rights

Subject to applicable law, you have rights over your personal data. To exercise any of them, email contact@thegoodpicture.com. We respond within 30 days and may ask you to verify your identity first.

Under the GDPR (EU/EEA/UK) and the Kenya Data Protection Act, 2019

  • Access — a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — delete your data (the “right to be forgotten”).
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — limit how we process your data.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where we rely on consent, withdraw it at any time.

You may also lodge a complaint with your supervisory authority — in Kenya, the Office of the Data Protection Commissioner (ODPC); in the EU/EEA, your local authority.

If you are a California resident (CCPA/CPRA)

You have the right to know, delete, and correct your personal information, and to opt out of its “sale” or “sharing”. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising your rights.

11.Security

We protect your data with encryption in transit and at rest, row-level access controls, encrypted integration tokens, least-privilege access, and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and review our practices regularly. Our full posture is described on the Security page.

12.Children’s data

Outsource is a business tool intended for professional use. It is not directed to, and we do not knowingly collect personal data from, anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

13.Breach notification

In the event of a personal-data breach likely to result in a risk to your rights, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Articles 33 and 34 and the equivalent Kenyan requirements.

14.Data Processing Agreement

Business customers who need a Data Processing Agreement (DPA) — for example where we process personal data on your behalf as your processor — can request one at contact@thegoodpicture.com. Our DPA incorporates the Standard Contractual Clauses and our current sub-processor list.

15.Changes to this policy

We may update this policy from time to time. For material changes, we will give at least 30 days’ notice by email and update the version and effective date above before the changes take effect.

16.Contact

For any privacy question, or to exercise a right, contact our data-protection contact at contact@thegoodpicture.com. The Good PictureNairobi, Kenya.