Data Processing Agreement

Last Updated: January 6, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Merchant" or "Data Controller") and Liva 7 (the "Processor") and governs the processing of Personal Data by Liva 7 on your behalf.

This DPA reflects our commitment to data protection, privacy, and compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and other relevant regulations.

1. Definitions

For the purposes of this DPA, the following terms have the meanings set out below:

  • Data Controller: The Merchant, who determines the purposes and means of processing Personal Data.
  • Data Processor: Liva 7, who processes Personal Data on behalf of the Merchant.
  • Personal Data: Any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
  • Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
  • Sub-processor: Any third party engaged by Liva 7 to process Personal Data on behalf of the Merchant.
  • Data Subject: An individual whose Personal Data is processed.
  • Applicable Laws: GDPR, CCPA, and any other relevant data protection or privacy legislation.

2. Scope of Processing

Liva 7 processes Personal Data solely on behalf of the Merchant and in accordance with the Merchant's documented instructions. The types of Personal Data processed may include:

  • Customer names, email addresses, and contact information
  • Order history and purchase behavior
  • Interaction data with AI-powered chat features
  • Device and browser information
  • Any other data submitted by the Merchant or collected through the Liva 7 app

The purpose of processing is to provide AI-driven customer engagement, support automation, and analytics services as described in our Terms of Service.

3. Merchant Responsibilities (Data Controller)

As the Data Controller, the Merchant is responsible for:

  • Ensuring that all Personal Data provided to Liva 7 is collected lawfully and with appropriate consent
  • Providing clear and accurate instructions to Liva 7 regarding the processing of Personal Data
  • Ensuring compliance with all applicable data protection laws
  • Informing Data Subjects about the processing of their Personal Data, including the involvement of Liva 7 as a Processor
  • Responding to Data Subject requests in accordance with applicable laws

4. Liva 7 Responsibilities (Data Processor)

As the Data Processor, Liva 7 commits to:

  • Processing Personal Data only in accordance with the Merchant's documented instructions
  • Implementing appropriate technical and organizational measures to protect Personal Data (see our Security Policy)
  • Ensuring that personnel authorized to process Personal Data are bound by confidentiality obligations
  • Assisting the Merchant in responding to Data Subject requests
  • Assisting the Merchant in ensuring compliance with data protection obligations
  • Deleting or returning Personal Data upon termination of services, unless retention is required by law
  • Making available all information necessary to demonstrate compliance with this DPA

5. Lawful Basis and Scope

Liva 7 processes Personal Data based on the Merchant's instructions and the contractual relationship between Liva 7 and the Merchant. The Merchant must ensure that a lawful basis exists for all processing activities, including:

  • Consent from Data Subjects
  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate interests, where applicable

6. Data Security Measures

Liva 7 implements industry-standard security measures to protect Personal Data from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Employee training on data protection and security best practices
  • Incident response and breach notification procedures

For a comprehensive overview of our security practices, please refer to our Security Policy.

7. Sub-processors

Liva 7 may engage third-party Sub-processors to assist in providing services. The Merchant authorizes Liva 7 to engage Sub-processors, provided that:

  • Liva 7 maintains a current list of Sub-processors
  • Liva 7 ensures that Sub-processors are bound by data protection obligations equivalent to those in this DPA
  • Liva 7 remains fully liable for the acts and omissions of Sub-processors
  • The Merchant is notified of any changes to Sub-processors and has the opportunity to object

Current Sub-processors may include cloud hosting providers, analytics services, and AI infrastructure partners. A full list is available upon request.

8. Data Retention and Deletion

Liva 7 retains Personal Data only for as long as necessary to fulfill the purposes outlined in this DPA or as required by law. Upon termination of services or upon the Merchant's request, Liva 7 will:

  • Delete or anonymize all Personal Data within 30 days, unless legal obligations require retention
  • Provide confirmation of deletion upon request
  • Ensure that Sub-processors also delete or return Personal Data

Merchants may request data deletion at any time by contacting our support team.

9. International Data Transfers

Liva 7 may transfer Personal Data to countries outside the European Economic Area (EEA) or the Merchant's jurisdiction. In such cases, Liva ensures that:

  • Transfers are made to countries with an adequate level of data protection as determined by the European Commission or other relevant authorities
  • Appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)
  • The Merchant is informed of the legal mechanisms used to protect transferred data

10. Data Subject Rights

Liva 7 will assist the Merchant in fulfilling Data Subject requests, including:

  • Right of Access: Providing Data Subjects with access to their Personal Data
  • Right to Rectification: Correcting inaccurate or incomplete Personal Data
  • Right to Erasure: Deleting Personal Data when no longer necessary or upon request
  • Right to Restriction: Limiting the processing of Personal Data under certain conditions
  • Right to Data Portability: Providing Personal Data in a structured, commonly used format
  • Right to Object: Allowing Data Subjects to object to certain types of processing

Liva 7 will respond to Data Subject requests forwarded by the Merchant within a reasonable timeframe and in accordance with applicable laws.

11. Incident Response and Breach Notification

In the event of a Personal Data breach, Liva 7 will:

  • Notify the Merchant without undue delay and no later than 72 hours after becoming aware of the breach
  • Provide details of the breach, including the nature of the incident, categories and approximate number of affected Data Subjects, and potential consequences
  • Describe the measures taken or proposed to address the breach and mitigate its effects
  • Cooperate with the Merchant in investigating and resolving the breach
  • Assist the Merchant in notifying Data Subjects and regulatory authorities, if required

Liva 7 maintains a comprehensive incident response plan to minimize the impact of any security incidents.

12. Audits and Compliance

Liva 7 will make available to the Merchant all information necessary to demonstrate compliance with this DPA and applicable data protection laws. The Merchant may conduct audits or inspections, subject to:

  • Reasonable notice (at least 30 days in advance)
  • Execution of a confidentiality agreement
  • Conducting audits during normal business hours and in a manner that does not disrupt Liva 7's operations

Liva 7 may provide audit reports or certifications from independent third parties in lieu of on-site audits.

13. Updates to This DPA

Liva 7 may update this DPA from time to time to reflect changes in our practices, legal requirements, or industry standards. We will notify Merchants of material changes by:

  • Posting the updated DPA on our website
  • Sending an email notification to the Merchant's registered email address
  • Providing at least 30 days' notice before the changes take effect

Continued use of Liva 7 services after the effective date of changes constitutes acceptance of the updated DPA.

Contact Information

If you have any questions about this Data Processing Agreement or our data protection practices, please contact us:

Email: support@liva7.com

Data Protection Officer: support@liva7.com