DRAFT — Not yet reviewed by an attorney This is a template for use with Business Layer customers who need GDPR/CCPA-style processor terms. It has not been reviewed by a lawyer and has not yet been signed by anyone.
← Back to LIVIN OS

Data Processing Agreement

Template version: July 16, 2026

1. Purpose & scope 2. Roles 3. Details of processing 4. Sub-processors 5. Security measures 6. Assistance with data subject rights 7. Data breach notification 8. International transfers 9. Deletion & return of data 10. Audit rights 11. Liability

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or Terms of Service between Livin LLC ("Processor," "we") and the business entering into this agreement ("Customer," "Controller"), and applies whenever we process personal data on Customer's behalf in connection with the Service — most relevantly, LIVIN OS's Business Layer offerings such as Business Receptionist.

1. Purpose & scope

This DPA reflects the parties' agreement on the processing of personal data in accordance with applicable data protection law, including (where applicable) the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA").

2. Roles

Customer is the Controller (or "Business" under CCPA) of the personal data it submits to or collects through the Service — for example, its own end-customers' contact details, call transcripts, or booking information. LIVIN acts as the Processor (or "Service Provider" under CCPA), processing that data only on Customer's documented instructions and only to provide the Service.

3. Details of processing

Subject matterProvision of the LIVIN OS Business Layer service (e.g. AI-powered lead capture, appointment booking, call/chat handling) to Customer.
DurationFor the term of the underlying Master Service Agreement, plus any post-termination period needed for deletion or return of data under Section 9.
Nature & purposeReceiving, storing, and processing Customer's end-user contact and interaction data in order to provide lead capture, routing, scheduling, and AI-assisted response generation.
Categories of data subjectsCustomer's own customers, prospects, or callers who interact with Customer's deployment of the Service.
Categories of personal dataName, contact details (phone/email), messages or call content, appointment details, and any other information a data subject voluntarily provides during the interaction.

4. Sub-processors

Customer authorizes LIVIN to engage the following sub-processors, and any others LIVIN adds with 30 days' advance notice to Customer (during which Customer may object on reasonable data-protection grounds):

Sub-processorFunctionLocation
Anthropic, PBCAI response generationUnited States
Supabase, Inc.Database hosting & authenticationUnited States (region-configurable)
Vercel, Inc.Application hostingUnited States
Stripe, Inc.Payment processing (where applicable)United States
Cloudflare, Inc.Content delivery / static file hostingGlobal CDN

LIVIN remains responsible for each sub-processor's compliance with data-protection obligations equivalent to those in this DPA.

5. Security measures

LIVIN implements appropriate technical and organizational measures, including: encryption of data in transit (TLS/HTTPS); encryption at rest for sensitive fields; row-level security limiting each account to its own data; access controls limiting internal access to what's needed to operate the Service; and, for products built with client-side encryption (such as LIVIN Vault), true end-to-end encryption under which LIVIN has no technical ability to read the underlying content.

6. Assistance with data subject rights

LIVIN will provide reasonable assistance to Customer in responding to requests from data subjects to exercise their rights (access, deletion, correction, portability, objection) under applicable law, to the extent Customer cannot reasonably fulfill the request itself using the Service's own functionality.

7. Data breach notification

LIVIN will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any confirmed unauthorized access to or disclosure of personal data processed on Customer's behalf, and will provide reasonably available details to help Customer meet its own notification obligations.

8. International transfers

Where personal data is transferred outside the European Economic Area, UK, or Switzerland, the parties will rely on an appropriate transfer mechanism (such as the European Commission's Standard Contractual Clauses) to the extent required by applicable law. [PLACEHOLDER — if Customer has EU/UK data subjects, incorporate the current SCC modules by reference here; recommend counsel confirm the correct module set for a controller-to-processor relationship.]

9. Deletion & return of data

On termination of the underlying agreement, LIVIN will, at Customer's choice, delete or return all personal data processed on Customer's behalf within 30 days, except where retention is required by law.

10. Audit rights

LIVIN will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, on reasonable notice and no more than once per year absent a suspected breach.

11. Liability

Each party's liability under this DPA is subject to the limitation of liability provisions in the underlying Master Service Agreement or Terms of Service.

For counsel: this template assumes a relatively small-scale, U.S.-based processor relationship. If a specific Business Layer customer is large, EU-based, or in a regulated industry (healthcare, finance), this template should be reviewed and likely expanded before signature — particularly Sections 4 and 8.