Privacy policy
1. Who we are
Supervenient is a UK company building Picnic, a collaboration platform for teams working alongside AI.
- Legal entity: Supervenient Limited
- Company number: 17202681, registered in England and Wales
- ICO registration: ZC210817
- Privacy contact: dataprotection@supervenient.ai
In this policy, "we", "us" and "Supervenient" mean the entity above.
2. What this policy covers
This policy applies to:
- supervenient.ai — our website, including the waiting list and investor enquiry forms
- withpicnic.xyz and the Picnic application — our product, currently available by invitation to organisations
It does not cover third-party sites we link to, or the internal privacy practices of organisations that use Picnic. Those organisations set their own policies for their own people.
3. The two roles we play
This distinction matters, and it determines which parts of this policy apply to you.
We are the controller — deciding why and how information is used — for the people we deal with directly. That means website visitors, people on the waiting list, investors, the administrators and users of customer accounts, and anyone who emails us. Sections 4 to 6 cover this.
We are the processor — acting only on a customer's documented instructions — for the material an organisation puts into Picnic. If your employer uses Picnic and you want to know why your data is in there or ask for it to be removed, your employer is the controller and the first place to ask. Section 7 covers this.
Picnic is sold to organisations only. We do not offer individual consumer accounts.
4. Information we collect as controller
Website visitors
We use privacy-friendly, cookieless analytics. It records aggregate page views, referring site, approximate country, browser and device type. It does not set cookies, does not track you across other websites, and does not build a profile of you. We cannot identify individual visitors from it.
Our servers also produce standard technical logs, which may include IP addresses, for security and troubleshooting.
Waiting list and investor enquiries
When you use a form on our site we collect what you give us — typically your name, email address, organisation, role, and anything you write in a free-text field. Investor enquiries may additionally include your firm, fund stage and areas of focus.
Picnic account holders
For people using Picnic under their organisation's account: name, work email address, role and permissions, authentication identifiers, and records of your activity in the product (sign-ins, actions taken, features used). Where a customer connects a messaging channel such as Slack, Microsoft Teams or WhatsApp, this includes the account identifiers needed to route messages.
Correspondence
Emails, support requests and meeting notes, retained so we have a record of what was discussed.
Job applicants
Applications, CVs and interview notes, where you apply to us directly.
5. Why we use it, and our lawful basis
| What we do | Lawful basis |
|---|---|
| Operate the website and keep it secure | Legitimate interests — running a safe service |
| Measure aggregate site usage | Legitimate interests — understanding what's useful; no cookies or profiling |
| Manage the waiting list and tell you when Picnic opens up | Consent, or legitimate interests where you asked to be added |
| Respond to investor enquiries and manage fundraising | Legitimate interests — raising investment |
| Provide Picnic to a customer, including account administration | Performance of a contract, or legitimate interests where the contract is with your employer |
| Bill customers and keep accounting records | Contract and legal obligation |
| Improve the product using aggregate, non-identifying usage patterns | Legitimate interests |
| Prevent fraud, abuse and security incidents | Legitimate interests, legal obligation |
| Consider job applications | Steps prior to entering a contract |
Where we rely on legitimate interests, we have weighed those interests against your rights and concluded they do not override them. Ask us and we'll explain the reasoning for any specific use.
We do not sell personal data, and we do not share it with third parties for their own marketing.
6. Marketing
If you join the waiting list or contact us as an investor, we'll email you about Picnic and about Supervenient. Every message has an unsubscribe link, and you can also reply and ask us to stop. We won't pass your details to anyone else to market to you.
7. Customer Content: our role as processor
"Customer Content" means everything an organisation and its people put into Picnic — messages, documents, files, project context, briefs, client material, and the memory and knowledge that Picnic builds from them.
For this material:
- The customer organisation is the controller. We process it only on their documented instructions, under a data processing agreement.
- We use it to provide the service to that customer. We do not use it to train models — ours or anyone else's. See our AI policy for the detail.
- We keep it logically separated by tenant, so one customer's content is not accessible to another.
- Access by our staff is restricted to what is needed to run and support the service, is logged, and is granted on a least-privilege basis.
- The customer decides what goes in. They are responsible for having a lawful basis for it, for informing their own people, and for not putting in special category data or anything else they aren't permitted to share.
If you are an individual whose information appears in a customer's Picnic account and you want it corrected or removed, contact that organisation. If you contact us instead, we will pass the request on and help them respond, but we cannot act on it independently.
8. Sub-processors
We use a small number of specialist providers. Each is bound by written terms requiring confidentiality, security measures and processing only on our instructions.
| Provider | Purpose | Processing location |
|---|---|---|
| Amazon Web Services | Hosting, compute, storage and model inference via Bedrock | UK / EU (eu-west-2) and US (us-east-1) |
| Microsoft | Email and document storage | EU |
| AI inference providers (please see list in our AI policy) | AI responses | Various (see AI policy) |
Messaging platforms a customer chooses to connect — Slack, Microsoft Teams, WhatsApp — are not our sub-processors. The customer's relationship with those platforms is their own, and the platform's terms apply to data held there.
We maintain the current list at this page. Customers under contract receive advance notice of any new or replacement sub-processor and may object on reasonable data protection grounds.
9. Where data goes
Our primary processing is in the UK and EU. Personal data stays there wherever we can arrange it.
Some providers, marked above, process data in the United States. Where that happens we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with a transfer risk assessment and supplementary technical measures including encryption in transit and at rest.
Customers who need processing restricted entirely to the UK and EU should talk to us before signing — we can configure a reduced provider set, with some effect on available capabilities.
10. Security
We take a proportionate but serious approach:
- Encryption in transit (TLS) and at rest
- Tenant isolation so customer data is separated
- Role-based access control and least privilege for staff access
- Multi-factor authentication on administrative systems
- Audit logging of access to production systems and customer data
- Secrets managed through a dedicated secrets manager, never in source control
- Regular dependency and vulnerability patching
- Access reviews when someone joins, changes role or leaves
No system is perfectly secure. If we suffer a personal data breach that poses a risk to people, we will notify the ICO within 72 hours where required, and tell affected customers without undue delay so they can meet their own obligations.
11. How long we keep things
| Data | Retention |
|---|---|
| Waiting list entries | Until you unsubscribe, or 24 months after your last engagement |
| Investor correspondence and records | 6 years, given their relevance to our corporate and financial records |
| Picnic account records | For the life of the account |
| Customer Content after an account closes | 90 days, then permanent deletion, unless the contract says otherwise or the customer asks for earlier deletion |
| Backups containing Customer Content | Rolling cycle, overwritten within 30 days of deletion |
| Security and application logs | 3 years |
| Support correspondence | 3 years from last contact |
| Accounting and tax records | 6 years, as required by UK law |
| Unsuccessful job applications | 6 months, unless you agree to us keeping them longer |
12. Your rights
Under UK GDPR you have the right to: be told what we hold and get a copy of it; have inaccurate information corrected; have information deleted; restrict or object to how we use it; receive it in a portable format; and withdraw consent where consent is what we relied on. You can also object to direct marketing at any time, and we must stop.
To exercise any of these, email dataprotection@supervenient.ai. We'll respond within one month. We may ask you to confirm your identity first.
If you are unhappy with how we've handled your information, please tell us so we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk, by phone on 0303 123 1113, or in writing to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
If you are in the EU, you may complain to your local supervisory authority.
13. Cookies
Our website sets no tracking cookies and uses no cookie-based analytics, which is why you won't see a consent banner.
The Picnic application sets strictly necessary cookies to keep you signed in and to protect against cross-site request forgery. These are exempt from consent requirements because the service cannot work without them. We do not use advertising, retargeting or third-party tracking cookies anywhere.
14. Children
Picnic is a business product and is not directed at anyone under 18. We do not knowingly collect information about children. If you believe we have, tell us and we'll delete it.
15. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects using solely automated processing. Picnic uses AI to draft, suggest, summarise and route work, but our terms require that consequential decisions remain with a person. Our AI policy explains how we hold that line.
16. Changes
We'll update this policy as the product develops. Material changes will be notified by email to customers and waiting list members, and the version and date at the top will always tell you which version you're reading.