Privacy policy

Version 1.0 · Effective 31st July 2026

1. Who we are

Supervenient is a UK company building Picnic, a collaboration platform for teams working alongside AI.

In this policy, "we", "us" and "Supervenient" mean the entity above.

2. What this policy covers

This policy applies to:

It does not cover third-party sites we link to, or the internal privacy practices of organisations that use Picnic. Those organisations set their own policies for their own people.

3. The two roles we play

This distinction matters, and it determines which parts of this policy apply to you.

We are the controller — deciding why and how information is used — for the people we deal with directly. That means website visitors, people on the waiting list, investors, the administrators and users of customer accounts, and anyone who emails us. Sections 4 to 6 cover this.

We are the processor — acting only on a customer's documented instructions — for the material an organisation puts into Picnic. If your employer uses Picnic and you want to know why your data is in there or ask for it to be removed, your employer is the controller and the first place to ask. Section 7 covers this.

Picnic is sold to organisations only. We do not offer individual consumer accounts.

4. Information we collect as controller

Website visitors

We use privacy-friendly, cookieless analytics. It records aggregate page views, referring site, approximate country, browser and device type. It does not set cookies, does not track you across other websites, and does not build a profile of you. We cannot identify individual visitors from it.

Our servers also produce standard technical logs, which may include IP addresses, for security and troubleshooting.

Waiting list and investor enquiries

When you use a form on our site we collect what you give us — typically your name, email address, organisation, role, and anything you write in a free-text field. Investor enquiries may additionally include your firm, fund stage and areas of focus.

Picnic account holders

For people using Picnic under their organisation's account: name, work email address, role and permissions, authentication identifiers, and records of your activity in the product (sign-ins, actions taken, features used). Where a customer connects a messaging channel such as Slack, Microsoft Teams or WhatsApp, this includes the account identifiers needed to route messages.

Correspondence

Emails, support requests and meeting notes, retained so we have a record of what was discussed.

Job applicants

Applications, CVs and interview notes, where you apply to us directly.

5. Why we use it, and our lawful basis

What we doLawful basis
Operate the website and keep it secureLegitimate interests — running a safe service
Measure aggregate site usageLegitimate interests — understanding what's useful; no cookies or profiling
Manage the waiting list and tell you when Picnic opens upConsent, or legitimate interests where you asked to be added
Respond to investor enquiries and manage fundraisingLegitimate interests — raising investment
Provide Picnic to a customer, including account administrationPerformance of a contract, or legitimate interests where the contract is with your employer
Bill customers and keep accounting recordsContract and legal obligation
Improve the product using aggregate, non-identifying usage patternsLegitimate interests
Prevent fraud, abuse and security incidentsLegitimate interests, legal obligation
Consider job applicationsSteps prior to entering a contract

Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. Ask us and we'll explain the reasoning for any specific use.

We do not sell personal data, and we do not share it with third parties for their own marketing.

6. Marketing

If you join the waiting list or contact us as an investor, we'll email you about Picnic and about Supervenient. Every message has an unsubscribe link, and you can also reply and ask us to stop. We won't pass your details to anyone else to market to you.

7. Customer Content: our role as processor

"Customer Content" means everything an organisation and its people put into Picnic — messages, documents, files, project context, briefs, client material, and the memory and knowledge that Picnic builds from them.

For this material:

If you are an individual whose information appears in a customer's Picnic account and you want it corrected or removed, contact that organisation. If you contact us instead, we will pass the request on and help them respond, but we cannot act on it independently.

8. Sub-processors

We use a small number of specialist providers. Each is bound by written terms requiring confidentiality, security measures and processing only on our instructions.

ProviderPurposeProcessing location
Amazon Web ServicesHosting, compute, storage and model inference via BedrockUK / EU (eu-west-2) and US (us-east-1)
MicrosoftEmail and document storageEU
AI inference providers (please see list in our AI policy)AI responsesVarious (see AI policy)

Messaging platforms a customer chooses to connect — Slack, Microsoft Teams, WhatsApp — are not our sub-processors. The customer's relationship with those platforms is their own, and the platform's terms apply to data held there.

We maintain the current list at this page. Customers under contract receive advance notice of any new or replacement sub-processor and may object on reasonable data protection grounds.

9. Where data goes

Our primary processing is in the UK and EU. Personal data stays there wherever we can arrange it.

Some providers, marked above, process data in the United States. Where that happens we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary technical measures including encryption in transit and at rest.

Customers who need processing restricted entirely to the UK and EU should talk to us before signing — we can configure a reduced provider set, with some effect on available capabilities.

10. Security

We take a proportionate but serious approach:

No system is perfectly secure. If we suffer a personal data breach that poses a risk to people, we will notify the ICO within 72 hours where required, and tell affected customers without undue delay so they can meet their own obligations.

11. How long we keep things

DataRetention
Waiting list entriesUntil you unsubscribe, or 24 months after your last engagement
Investor correspondence and records6 years, given their relevance to our corporate and financial records
Picnic account recordsFor the life of the account
Customer Content after an account closes90 days, then permanent deletion, unless the contract says otherwise or the customer asks for earlier deletion
Backups containing Customer ContentRolling cycle, overwritten within 30 days of deletion
Security and application logs3 years
Support correspondence3 years from last contact
Accounting and tax records6 years, as required by UK law
Unsuccessful job applications6 months, unless you agree to us keeping them longer

12. Your rights

Under UK GDPR you have the right to: be told what we hold and get a copy of it; have inaccurate information corrected; have information deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent where consent is what we relied on. You can also object to direct marketing at any time, and we must stop.

To exercise any of these, email dataprotection@supervenient.ai. We'll respond within one month. We may ask you to confirm your identity first.

If you are unhappy with how we've handled your information, please tell us so we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

If you are in the EU, you may complain to your local supervisory authority.

13. Cookies

Our website sets no tracking cookies and uses no cookie-based analytics, which is why you won't see a consent banner.

The Picnic application sets strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These are exempt from consent requirements because the service cannot work without them. We do not use advertising, retargeting or third-party tracking cookies anywhere.

14. Children

Picnic is a business product and is not directed at anyone under 18. We do not knowingly collect information about children. If you believe we have, tell us and we'll delete it.

15. Automated decision-making

We do not make decisions about you that produce legal or similarly significant effects using solely automated processing. Picnic uses AI to draft, suggest, summarise and route work, but our terms require that consequential decisions remain with a person. Our AI policy explains how we hold that line.

16. Changes

We'll update this policy as the product develops. Material changes will be notified by email to customers and waiting list members, and the version and date at the top will always tell you which version you're reading.

17. Contact

privacy@supervenient.ai

← Back home