Woovly India Pvt Ltd (operating as Live2.ai)
Version: 2.0 Effective Date: 17 September 2026 Supersedes: the Privacy Policy previously published at https://live2.ai/legal/privacy-policy (undated) Published at: https://live2.ai/legal/privacy-policy
Companion document. Where we process personal data on behalf of a business customer, our Data Protection Addendum (v2.0) governs that processing and forms part of our Terms of Service. This Privacy Policy and the DPA are maintained together; the vendors, retention periods, storage locations and contacts stated here are the same as those stated there.
Woovly India Pvt Ltd, a company incorporated in India, operating under the brand Live2.ai, is the data controller (under the EU and UK GDPR), the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023) and the Business (under the CCPA) in respect of the personal data described in this Policy.
| Registered office | HSR Layout, Bengaluru, Karnataka, India |
| General privacy enquiries | [email protected] |
| Data Protection Officer | Yash Arora — [email protected] |
| Grievance Officer (India) | Yash Arora — [email protected] |
| Security / incident reporting | [email protected] |
Our Data Protection Officer and Grievance Officer are based in India. We aim to acknowledge every enquiry within three (3) business days and to give a substantive response within thirty (30) days.
This Policy explains how we handle personal data when:
Where we act only as a processor. For use cases 3, 4 and 5, we usually act as a processor / Data Processor on behalf of our business customer, who decides what content is analysed and why. In those cases the customer is the controller and its own privacy notice governs; our role is set out in our DPA. We have still described that processing below so you can see what happens to your data.
| Data | IP address, device and browser type, operating system, pages viewed, referring URL, timestamps, cookie and session identifiers |
| Why | To operate and secure the Website, analyse traffic, and improve our content |
| Basis — EU/UK | Legitimate interests (running and securing our site); consent for non-essential cookies |
| Basis — India | Consent, obtained at the point of collection |
| Data | Full name, business email, phone number, job title, company name, country, hashed credentials, role and permissions, login history, billing contact details, and content you upload (video, images, captions, brand guidelines) |
| Why | To create and administer your account; provide the Platform; publish and schedule your content; generate audit findings and reports; provide support; send service communications; process payments; enforce our terms; prevent misuse |
| Basis — EU/UK | Performance of a contract; legitimate interests (service improvement, security, fraud prevention); consent for marketing |
| Basis — India | Consent, and performance of the contract with you |
Payment card details are collected and processed directly by our payment gateway (Razorpay). We do not see or store them.
| Data | IP address, device identifiers, interaction events (views, clicks, dwell time), and any comment, name, email or phone number you choose to submit |
| Why | To display the content, record interactions, and report engagement to our customer |
| Role | We act as processor for our customer |
| Data | Email address and preferences (for example, saved videos) |
| Why | To register you, send registration emails, and save your preferences |
| Sharing | We share this data with the customer whose website you registered from. That customer is a separate controller and its own privacy notice applies |
| Data | Name, email address, phone number, company name, job title, country, and the content of your messages |
| Why | To answer questions, provide support, manage supplier and customer relationships, and — where you have agreed — send marketing |
| Basis — EU/UK | Legitimate interests; consent for marketing |
| Basis — India | Consent |
This is the category most people do not expect, so we set it out plainly.
Our Platform analyses content that has already been published on social media. Where a customer connects its own accounts, or configures the Platform to monitor specified public accounts — for example, creators it has engaged, or accounts it benchmarks against — we ingest and analyse that published content.
| Data | Social handle, display name, profile picture, biography, platform user ID, public follower counts, published posts and captions, images, video, audio, hashtags, publicly visible comments and their authors, engagement counts, and any personal data appearing within that content |
| Why | To assess published content against the customer's brand guidelines and campaign criteria, and to produce audit findings and reports for that customer |
| Role | We act as a processor for the customer. The customer decides which accounts are monitored and is responsible for the lawfulness of that decision, and for providing notice where required |
| Basis — EU/UK | Determined by the customer as controller, typically legitimate interests |
| Basis — India | Where content has been made publicly available by the individual themselves, Section 3(c)(ii) of the DPDP Act provides that the Act does not apply to it. We nevertheless apply the security, retention and deletion safeguards in this Policy to it |
What we do not do. We do not build profiles of individuals for sale, sell or share this data, enrich it with data from brokers, or use it to train AI models. See Sections 4 and 6.
We may also use any of the above personal data to detect and prevent fraud and illegal activity, fix errors, conduct audits, maintain security, comply with law, respond to lawful requests from authorities, and establish or defend legal claims.
The DPDP Act does not recognise "legitimate interests" as a lawful basis. For individuals in India we rely on consent, or on one of the narrow "certain legitimate uses" in Section 7 of the DPDP Act. Where this Policy cites legitimate interests, that basis applies only under the EU and UK GDPR.
We do not seek, and ask you not to send us, special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — nor government identification numbers or payment card numbers.
Published social media content can incidentally contain such information; for example, a person's appearance may be visible in an image. We do not derive, infer, classify, index or make searchable any such characteristic, and we operate no feature that identifies people by them.
Our Platform uses artificial intelligence to analyse published content. We think you should know exactly how that works.
What runs on our own systems. Image and video understanding, demographic inference, speech-to-text transcription and optical character recognition all run inside our own infrastructure in India. Raw images, video frames, audio and any facial imagery are processed there and are never sent to a third-party AI provider.
What leaves our systems. Only derived text — transcripts, text extracted from images, the structured output of our own vision model, and the customer's compiled brand rules — is sent to external language models for scoring and reasoning. These are:
| Provider | Purpose | Safeguards |
|---|---|---|
| OpenAI | Compliance scoring, rule matching, feedback generation | Zero Data Retention enabled; contractual no-training commitment under the OpenAI DPA |
| Google Cloud Vertex AI | Text embeddings for content and rule matching | Processed in our India region; no use of customer data to train foundation models |
We do not use your personal data or your content to train AI models — not our own, and not anyone else's. This is a contractual commitment, flowed down to every AI provider we use. We do not route data through consumer-tier AI services or third-party AI gateways.
No automated decisions about you. Our outputs are analytical and advisory, produced for a customer's team to review and act on. We do not make decisions about individuals by automated means that produce legal or similarly significant effects (Article 22 GDPR).
We use cookies and similar technologies on our Website and Platform.
| Type | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing | No |
| Functional | Remembering preferences and settings | Yes, in the EU/UK and India |
| Analytics | Understanding how the Website and Platform are used | Yes, in the EU/UK and India |
Where consent is required we ask for it before setting non-essential cookies, and you can change or withdraw your choice at any time through the cookie settings link in the Website footer. Withdrawing consent is as straightforward as giving it.
You can also block cookies in your browser, and opt out of Google Analytics specifically using Google's opt-out browser add-on.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We share personal data with the service providers below, each under a written data processing agreement that obliges them to protect it and to use it only for the purpose stated.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, databases, storage, backups | India — asia-south1 (Mumbai), failover asia-south2 (Delhi NCR) |
| MongoDB Atlas | Application database | India — asia-south1 (Mumbai) |
| Cloudflare | Web application firewall, DDoS protection, CDN | Global edge, India-preferred routing |
| Google Workspace | Business email and documents | India |
| Razorpay | Payment gateway (independent controller for card data) | India |
| Zoho | Invoicing | India |
| Provider | Purpose | Location |
|---|---|---|
| New Relic | Application performance monitoring, error alerting | USA |
| Sentry | Error monitoring and alerting | USA |
| Atlassian | Work management and support ticketing | USA |
| Slack | Internal messaging, incident coordination | USA |
| GitHub | Source code version control (no customer personal data in the ordinary course) | USA |
| Provider | Purpose | Location |
|---|---|---|
| Google Analytics | Website usage analytics | USA / EU |
| Hotjar | Product analytics on our marketing and administrative pages only — not deployed in the customer-facing Platform | Malta / EU |
| Redash | Internal analytics | USA |
OpenAI and Google Cloud Vertex AI, as described in Section 4.
We may also disclose personal data:
Where our customer configures an integration with a third-party service, content is shared with that service at the customer's instruction and under the customer's control, not ours.
We store personal data primarily on Google Cloud Platform in India (asia-south1, Mumbai), with failover to asia-south2 (Delhi NCR). Our teams access it from our offices in India.
Some of the providers listed in Section 6 process personal data outside India, including in the United States and the EU.
Transfers out of the EU, UK and Switzerland. Where we transfer personal data from these regions to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, as modified by the UK International Data Transfer Addendum for UK transfers and adapted for Switzerland. Details are in Section 8 of our DPA. You can request a copy of the relevant safeguards from [email protected].
Transfers out of India. We comply with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules. India permits transfers except to countries the Central Government restricts by notification; we monitor those notifications and will relocate processing if a provider's location becomes restricted.
| Data | Retention |
|---|---|
| Account data | For the life of your account, then deleted within 30 days of closure |
| Content ingested for audit, and audit findings | Configurable by the customer — 12, 24 or 36 months from ingestion; default 24 months |
| Security, access and audit logs | 12 months minimum (required by Rule 6 of the DPDP Rules), 18 months maximum |
| Backups | Rolling cycle, purged within 90 days |
| Support correspondence | 24 months from closure of the request |
| Marketing contact data | Until you opt out, then suppressed |
| Billing, financial and tax records | 8 years (section 128, Companies Act 2013, and applicable tax law) |
| Data subject to a deletion request | Deleted within 30 days |
We delete or anonymise personal data once the purpose for which we collected it has been served and no legal obligation requires us to keep it, as required by Section 8(7) of the DPDP Act.
| Right | EU / UK | India | California |
|---|---|---|---|
| Know what data we hold and how we use it | ✓ | ✓ | ✓ |
| Get a copy of your data | ✓ | ✓ | ✓ |
| Correct inaccurate data | ✓ | ✓ | ✓ |
| Delete your data | ✓ | ✓ | ✓ |
| Restrict how we use it | ✓ | — | — |
| Object to our use of it | ✓ | — | — |
| Data portability | ✓ | — | ✓ |
| Withdraw consent at any time | ✓ | ✓ | — |
| Nominate someone to exercise your rights if you die or become incapacitated | — | ✓ (s.14 DPDP) | — |
| Opt out of sale or sharing | — | — | ✓ (we do neither) |
| Complain to a regulator | ✓ | ✓ | ✓ |
| Not be discriminated against for exercising a right | — | — | ✓ |
Email [email protected], or the Grievance Officer at [email protected]. We may ask for information to verify your identity. We will acknowledge within three (3) business days and respond substantively within thirty (30) days. Deletion requests are actioned within thirty (30) days.
There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline — and we will explain why.
Where we rely on your consent, you can withdraw it at any time, and doing so is as easy as giving it — by emailing [email protected], through the cookie settings link, or via the unsubscribe link in any marketing email. Withdrawal does not affect processing carried out before you withdrew.
Email [email protected]. We will delete your account data within 30 days, subject to the retention exceptions in Section 8.
Note that if you have posted content publicly through a customer's site, that content may have been copied or cached by others beyond our control. We will delete our copies; we cannot delete theirs.
Use the unsubscribe link in any marketing email, or email [email protected]. We action opt-outs promptly.
Please come to us first, at [email protected] or [email protected] — we would rather fix it. You also have the right to complain to a regulator:
Our Website, Platform and services are not intended for children, and we do not knowingly collect personal data from anyone under eighteen (18).
In line with Section 9(3) of the DPDP Act, we do not track or behaviourally monitor children, do not serve advertising directed at children, and operate no feature that estimates or infers a person's age.
If you are under 18, please do not send us your personal data. If we learn that we hold a child's personal data without a lawful basis, we will delete it within thirty (30) days. If you believe we hold such data, contact [email protected].
We maintain an information security management system aligned to the requirements of ISO/IEC 27001:2022. Our measures include:
No system can be guaranteed secure. Please protect your own credentials and devices, and tell us at [email protected] if you suspect a problem.
If a personal data breach affects you, we will notify you and the relevant regulator as required — including the Data Protection Board of India within 72 hours under Rule 7 of the DPDP Rules, and the competent supervisory authority within 72 hours under Article 33 of the GDPR.
Our Website and Platform can link to or interact with services we do not control. We are not responsible for their privacy practices or content. Please read their own policies.
We review this Policy at least annually and update it as our services or the law change. The version number and effective date at the top always tell you which version applies. If we make a significant change to how we use personal data, we will post a notice on the Website and Platform and, where required, contact you directly. Previous versions are available on request.
| General privacy | [email protected] |
| Data Protection Officer | Yash Arora — [email protected] |
| Grievance Officer (India) | Yash Arora — [email protected] |
| Security | [email protected] |
| Post | Woovly India Pvt Ltd, HSR Layout, Bengaluru, Karnataka, India |
Nothing in this Policy limits your statutory rights or your access to any remedy.
LIVE2.AI APPS AVAILABLE ON

PRODUCTS
Shoppable Social Wall
Social Media Publishing & Reporting
Live2Shop.tv
SOLUTIONS
Content Solutions
Distribution & Growth
RESOURCES
Blog
Help Center/ Support Documentation
Integrations
FAQs
© 2026, Woovly India Pvt Ltd. All Rights Reserved.