Privacy Policy

Woovly India Pvt Ltd (operating as Live2.ai)

Version: 2.0 Effective Date: 17 September 2026 Supersedes: the Privacy Policy previously published at https://live2.ai/legal/privacy-policy (undated) Published at: https://live2.ai/legal/privacy-policy

Companion document. Where we process personal data on behalf of a business customer, our Data Protection Addendum (v2.0) governs that processing and forms part of our Terms of Service. This Privacy Policy and the DPA are maintained together; the vendors, retention periods, storage locations and contacts stated here are the same as those stated there.


1. Who we are

Woovly India Pvt Ltd, a company incorporated in India, operating under the brand Live2.ai, is the data controller (under the EU and UK GDPR), the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023) and the Business (under the CCPA) in respect of the personal data described in this Policy.

Registered officeHSR Layout, Bengaluru, Karnataka, India
General privacy enquiries[email protected]
Data Protection OfficerYash Arora — [email protected]
Grievance Officer (India)Yash Arora — [email protected]
Security / incident reporting[email protected]

Our Data Protection Officer and Grievance Officer are based in India. We aim to acknowledge every enquiry within three (3) business days and to give a substantive response within thirty (30) days.

2. When this Policy applies

This Policy explains how we handle personal data when:

  1. you visit our website at https://www.live2.ai ("Website");
  2. you are a customer, or a user authorised by a customer, of our platform ("Platform");
  3. you view or interact with content displayed through our Platform on a customer's website, app or e-commerce store;
  4. you register with us from a customer's website or store;
  5. you are a creator, influencer or social media account holder whose published content is analysed through our Platform (see Section 3.6);
  6. you contact us for support, or submit a request;
  7. you meet us at a marketing event or give us your details for marketing;
  8. you are a contact at one of our suppliers or customers; or
  9. you interact with our social media profiles.

Where we act only as a processor. For use cases 3, 4 and 5, we usually act as a processor / Data Processor on behalf of our business customer, who decides what content is analysed and why. In those cases the customer is the controller and its own privacy notice governs; our role is set out in our DPA. We have still described that processing below so you can see what happens to your data.

3. What we collect, why, and on what basis

3.1 Website visitors

DataIP address, device and browser type, operating system, pages viewed, referring URL, timestamps, cookie and session identifiers
WhyTo operate and secure the Website, analyse traffic, and improve our content
Basis — EU/UKLegitimate interests (running and securing our site); consent for non-essential cookies
Basis — IndiaConsent, obtained at the point of collection

3.2 Platform customers and their authorised users

DataFull name, business email, phone number, job title, company name, country, hashed credentials, role and permissions, login history, billing contact details, and content you upload (video, images, captions, brand guidelines)
WhyTo create and administer your account; provide the Platform; publish and schedule your content; generate audit findings and reports; provide support; send service communications; process payments; enforce our terms; prevent misuse
Basis — EU/UKPerformance of a contract; legitimate interests (service improvement, security, fraud prevention); consent for marketing
Basis — IndiaConsent, and performance of the contract with you

Payment card details are collected and processed directly by our payment gateway (Razorpay). We do not see or store them.

3.3 Viewers of content displayed through the Platform

DataIP address, device identifiers, interaction events (views, clicks, dwell time), and any comment, name, email or phone number you choose to submit
WhyTo display the content, record interactions, and report engagement to our customer
RoleWe act as processor for our customer

3.4 People who register from a customer's website

DataEmail address and preferences (for example, saved videos)
WhyTo register you, send registration emails, and save your preferences
SharingWe share this data with the customer whose website you registered from. That customer is a separate controller and its own privacy notice applies

3.5 Support, marketing, supplier and social media contacts

DataName, email address, phone number, company name, job title, country, and the content of your messages
WhyTo answer questions, provide support, manage supplier and customer relationships, and — where you have agreed — send marketing
Basis — EU/UKLegitimate interests; consent for marketing
Basis — IndiaConsent

3.6 Creators and social media account holders whose content we analyse

This is the category most people do not expect, so we set it out plainly.

Our Platform analyses content that has already been published on social media. Where a customer connects its own accounts, or configures the Platform to monitor specified public accounts — for example, creators it has engaged, or accounts it benchmarks against — we ingest and analyse that published content.

DataSocial handle, display name, profile picture, biography, platform user ID, public follower counts, published posts and captions, images, video, audio, hashtags, publicly visible comments and their authors, engagement counts, and any personal data appearing within that content
WhyTo assess published content against the customer's brand guidelines and campaign criteria, and to produce audit findings and reports for that customer
RoleWe act as a processor for the customer. The customer decides which accounts are monitored and is responsible for the lawfulness of that decision, and for providing notice where required
Basis — EU/UKDetermined by the customer as controller, typically legitimate interests
Basis — IndiaWhere content has been made publicly available by the individual themselves, Section 3(c)(ii) of the DPDP Act provides that the Act does not apply to it. We nevertheless apply the security, retention and deletion safeguards in this Policy to it

What we do not do. We do not build profiles of individuals for sale, sell or share this data, enrich it with data from brokers, or use it to train AI models. See Sections 4 and 6.

3.7 All categories

We may also use any of the above personal data to detect and prevent fraud and illegal activity, fix errors, conduct audits, maintain security, comply with law, respond to lawful requests from authorities, and establish or defend legal claims.

3.8 A note on lawful basis in India

The DPDP Act does not recognise "legitimate interests" as a lawful basis. For individuals in India we rely on consent, or on one of the narrow "certain legitimate uses" in Section 7 of the DPDP Act. Where this Policy cites legitimate interests, that basis applies only under the EU and UK GDPR.

3.9 What we do not collect

We do not seek, and ask you not to send us, special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — nor government identification numbers or payment card numbers.

Published social media content can incidentally contain such information; for example, a person's appearance may be visible in an image. We do not derive, infer, classify, index or make searchable any such characteristic, and we operate no feature that identifies people by them.

4. AI and automated processing

Our Platform uses artificial intelligence to analyse published content. We think you should know exactly how that works.

What runs on our own systems. Image and video understanding, demographic inference, speech-to-text transcription and optical character recognition all run inside our own infrastructure in India. Raw images, video frames, audio and any facial imagery are processed there and are never sent to a third-party AI provider.

What leaves our systems. Only derived text — transcripts, text extracted from images, the structured output of our own vision model, and the customer's compiled brand rules — is sent to external language models for scoring and reasoning. These are:

ProviderPurposeSafeguards
OpenAICompliance scoring, rule matching, feedback generationZero Data Retention enabled; contractual no-training commitment under the OpenAI DPA
Google Cloud Vertex AIText embeddings for content and rule matchingProcessed in our India region; no use of customer data to train foundation models

We do not use your personal data or your content to train AI models — not our own, and not anyone else's. This is a contractual commitment, flowed down to every AI provider we use. We do not route data through consumer-tier AI services or third-party AI gateways.

No automated decisions about you. Our outputs are analytical and advisory, produced for a customer's team to review and act on. We do not make decisions about individuals by automated means that produce legal or similarly significant effects (Article 22 GDPR).

5. Cookies and tracking

We use cookies and similar technologies on our Website and Platform.

TypePurposeConsent required
Strictly necessaryAuthentication, session management, security, load balancingNo
FunctionalRemembering preferences and settingsYes, in the EU/UK and India
AnalyticsUnderstanding how the Website and Platform are usedYes, in the EU/UK and India

Where consent is required we ask for it before setting non-essential cookies, and you can change or withdraw your choice at any time through the cookie settings link in the Website footer. Withdrawing consent is as straightforward as giving it.

You can also block cookies in your browser, and opt out of Google Analytics specifically using Google's opt-out browser add-on.

6. Who we share personal data with

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

We share personal data with the service providers below, each under a written data processing agreement that obliges them to protect it and to use it only for the purpose stated.

6.1 Infrastructure and operations

ProviderPurposeLocation
Google Cloud PlatformHosting, databases, storage, backupsIndia — asia-south1 (Mumbai), failover asia-south2 (Delhi NCR)
MongoDB AtlasApplication databaseIndia — asia-south1 (Mumbai)
CloudflareWeb application firewall, DDoS protection, CDNGlobal edge, India-preferred routing
Google WorkspaceBusiness email and documentsIndia
RazorpayPayment gateway (independent controller for card data)India
ZohoInvoicingIndia

6.2 Monitoring, support and internal tools

ProviderPurposeLocation
New RelicApplication performance monitoring, error alertingUSA
SentryError monitoring and alertingUSA
AtlassianWork management and support ticketingUSA
SlackInternal messaging, incident coordinationUSA
GitHubSource code version control (no customer personal data in the ordinary course)USA

6.3 Analytics

ProviderPurposeLocation
Google AnalyticsWebsite usage analyticsUSA / EU
HotjarProduct analytics on our marketing and administrative pages only — not deployed in the customer-facing PlatformMalta / EU
RedashInternal analyticsUSA

6.4 AI providers

OpenAI and Google Cloud Vertex AI, as described in Section 4.

6.5 Other sharing

We may also disclose personal data:

  • to regulators, courts, law enforcement and competent authorities where required by law or to respond to a valid legal request — we challenge requests that are not legally valid, and disclose only the minimum required;
  • to our staff and other entities in our group, on a need-to-know basis;
  • to a buyer or prospective buyer, in connection with a sale, merger, acquisition, insolvency or comparable transaction, subject to equivalent protections; and
  • where you have given consent.

Where our customer configures an integration with a third-party service, content is shared with that service at the customer's instruction and under the customer's control, not ours.

7. Where your data is stored, and international transfers

We store personal data primarily on Google Cloud Platform in India (asia-south1, Mumbai), with failover to asia-south2 (Delhi NCR). Our teams access it from our offices in India.

Some of the providers listed in Section 6 process personal data outside India, including in the United States and the EU.

Transfers out of the EU, UK and Switzerland. Where we transfer personal data from these regions to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, as modified by the UK International Data Transfer Addendum for UK transfers and adapted for Switzerland. Details are in Section 8 of our DPA. You can request a copy of the relevant safeguards from [email protected].

Transfers out of India. We comply with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules. India permits transfers except to countries the Central Government restricts by notification; we monitor those notifications and will relocate processing if a provider's location becomes restricted.

8. How long we keep personal data

DataRetention
Account dataFor the life of your account, then deleted within 30 days of closure
Content ingested for audit, and audit findingsConfigurable by the customer — 12, 24 or 36 months from ingestion; default 24 months
Security, access and audit logs12 months minimum (required by Rule 6 of the DPDP Rules), 18 months maximum
BackupsRolling cycle, purged within 90 days
Support correspondence24 months from closure of the request
Marketing contact dataUntil you opt out, then suppressed
Billing, financial and tax records8 years (section 128, Companies Act 2013, and applicable tax law)
Data subject to a deletion requestDeleted within 30 days

We delete or anonymise personal data once the purpose for which we collected it has been served and no legal obligation requires us to keep it, as required by Section 8(7) of the DPDP Act.

9. Your rights

9.1 Rights available to you

RightEU / UKIndiaCalifornia
Know what data we hold and how we use it
Get a copy of your data
Correct inaccurate data
Delete your data
Restrict how we use it
Object to our use of it
Data portability
Withdraw consent at any time
Nominate someone to exercise your rights if you die or become incapacitated✓ (s.14 DPDP)
Opt out of sale or sharing✓ (we do neither)
Complain to a regulator
Not be discriminated against for exercising a right

9.2 How to exercise them

Email [email protected], or the Grievance Officer at [email protected]. We may ask for information to verify your identity. We will acknowledge within three (3) business days and respond substantively within thirty (30) days. Deletion requests are actioned within thirty (30) days.

There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline — and we will explain why.

9.3 Withdrawing consent

Where we rely on your consent, you can withdraw it at any time, and doing so is as easy as giving it — by emailing [email protected], through the cookie settings link, or via the unsubscribe link in any marketing email. Withdrawal does not affect processing carried out before you withdrew.

9.4 Deleting your account

Email [email protected]. We will delete your account data within 30 days, subject to the retention exceptions in Section 8.

Note that if you have posted content publicly through a customer's site, that content may have been copied or cached by others beyond our control. We will delete our copies; we cannot delete theirs.

9.5 Marketing

Use the unsubscribe link in any marketing email, or email [email protected]. We action opt-outs promptly.

9.6 Complaints

Please come to us first, at [email protected] or [email protected] — we would rather fix it. You also have the right to complain to a regulator:

  • India — the Data Protection Board of India, under Section 13 of the DPDP Act, after raising the matter with our Grievance Officer.
  • EU — the supervisory authority in your country of residence, work, or where the issue arose.
  • UK — the Information Commissioner's Office, https://ico.org.uk.
  • Switzerland — the Federal Data Protection and Information Commissioner.

10. Children

Our Website, Platform and services are not intended for children, and we do not knowingly collect personal data from anyone under eighteen (18).

In line with Section 9(3) of the DPDP Act, we do not track or behaviourally monitor children, do not serve advertising directed at children, and operate no feature that estimates or infers a person's age.

If you are under 18, please do not send us your personal data. If we learn that we hold a child's personal data without a lawful basis, we will delete it within thirty (30) days. If you believe we hold such data, contact [email protected].

11. How we protect your data

We maintain an information security management system aligned to the requirements of ISO/IEC 27001:2022. Our measures include:

  • encryption in transit (TLS 1.2 or higher) and at rest (AES-256);
  • multi-factor authentication and single sign-on, least-privilege access, and quarterly access reviews;
  • logging and monitoring of access to personal data, with logs retained for at least 12 months;
  • regular vulnerability scanning and at least annual independent penetration testing;
  • encrypted backups with restoration testing, and a tested disaster recovery programme;
  • logical isolation of each customer's data in our multi-tenant environment; and
  • a documented incident response process.

No system can be guaranteed secure. Please protect your own credentials and devices, and tell us at [email protected] if you suspect a problem.

If a personal data breach affects you, we will notify you and the relevant regulator as required — including the Data Protection Board of India within 72 hours under Rule 7 of the DPDP Rules, and the competent supervisory authority within 72 hours under Article 33 of the GDPR.

12. Third-party services

Our Website and Platform can link to or interact with services we do not control. We are not responsible for their privacy practices or content. Please read their own policies.

13. Changes to this Policy

We review this Policy at least annually and update it as our services or the law change. The version number and effective date at the top always tell you which version applies. If we make a significant change to how we use personal data, we will post a notice on the Website and Platform and, where required, contact you directly. Previous versions are available on request.

14. Contact us

General privacy[email protected]
Data Protection OfficerYash Arora — [email protected]
Grievance Officer (India)Yash Arora — [email protected]
Security[email protected]
PostWoovly India Pvt Ltd, HSR Layout, Bengaluru, Karnataka, India

Nothing in this Policy limits your statutory rights or your access to any remedy.

Live2.ai logo

Follow us on

LIVE2.AI APPS AVAILABLE ON

Find us on Shopify

PRODUCTS

Shoppable Social Wall

Social Media Publishing & Reporting

Live2Shop.tv

SOLUTIONS

Content Solutions

Distribution & Growth

RESOURCES

Blog

Help Center/ Support Documentation

Integrations

FAQs

© 2026, Woovly India Pvt Ltd. All Rights Reserved.