This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or Terms of Service between Livin LLC ("Processor," "we") and the business entering into this agreement ("Customer," "Controller"), and applies whenever we process personal data on Customer's behalf in connection with the Service — most relevantly, LIVIN OS's Business Layer offerings such as Business Receptionist.
1. Purpose & scope
This DPA reflects the parties' agreement on the processing of personal data in accordance with applicable data protection law, including (where applicable) the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA").
2. Roles
Customer is the Controller (or "Business" under CCPA) of the personal data it submits to or collects through the Service — for example, its own end-customers' contact details, call transcripts, or booking information. LIVIN acts as the Processor (or "Service Provider" under CCPA), processing that data only on Customer's documented instructions and only to provide the Service.
3. Details of processing
| Subject matter | Provision of the LIVIN OS Business Layer service (e.g. AI-powered lead capture, appointment booking, call/chat handling) to Customer. |
|---|---|
| Duration | For the term of the underlying Master Service Agreement, plus any post-termination period needed for deletion or return of data under Section 9. |
| Nature & purpose | Receiving, storing, and processing Customer's end-user contact and interaction data in order to provide lead capture, routing, scheduling, and AI-assisted response generation. |
| Categories of data subjects | Customer's own customers, prospects, or callers who interact with Customer's deployment of the Service. |
| Categories of personal data | Name, contact details (phone/email), messages or call content, appointment details, and any other information a data subject voluntarily provides during the interaction. |
4. Sub-processors
Customer authorizes LIVIN to engage the following sub-processors, and any others LIVIN adds with 30 days' advance notice to Customer (during which Customer may object on reasonable data-protection grounds):
| Sub-processor | Function | Location |
|---|---|---|
| Anthropic, PBC | AI response generation | United States |
| Supabase, Inc. | Database hosting & authentication | United States (region-configurable) |
| Vercel, Inc. | Application hosting | United States |
| Stripe, Inc. | Payment processing (where applicable) | United States |
| Cloudflare, Inc. | Content delivery / static file hosting | Global CDN |
LIVIN remains responsible for each sub-processor's compliance with data-protection obligations equivalent to those in this DPA.
5. Security measures
LIVIN implements appropriate technical and organizational measures, including: encryption of data in transit (TLS/HTTPS); encryption at rest for sensitive fields; row-level security limiting each account to its own data; access controls limiting internal access to what's needed to operate the Service; and, for products built with client-side encryption (such as LIVIN Vault), true end-to-end encryption under which LIVIN has no technical ability to read the underlying content.
6. Assistance with data subject rights
LIVIN will provide reasonable assistance to Customer in responding to requests from data subjects to exercise their rights (access, deletion, correction, portability, objection) under applicable law, to the extent Customer cannot reasonably fulfill the request itself using the Service's own functionality.
7. Data breach notification
LIVIN will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of any confirmed unauthorized access to or disclosure of personal data processed on Customer's behalf, and will provide reasonably available details to help Customer meet its own notification obligations.
8. International transfers
Where personal data is transferred outside the European Economic Area, UK, or Switzerland, the parties will rely on an appropriate transfer mechanism (such as the European Commission's Standard Contractual Clauses) to the extent required by applicable law. [PLACEHOLDER — if Customer has EU/UK data subjects, incorporate the current SCC modules by reference here; recommend counsel confirm the correct module set for a controller-to-processor relationship.]
9. Deletion & return of data
On termination of the underlying agreement, LIVIN will, at Customer's choice, delete or return all personal data processed on Customer's behalf within 30 days, except where retention is required by law.
10. Audit rights
LIVIN will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, on reasonable notice and no more than once per year absent a suspected breach.
11. Liability
Each party's liability under this DPA is subject to the limitation of liability provisions in the underlying Master Service Agreement or Terms of Service.