Version history. The current version of this Addendum is always published at https://live2.ai/legal/dpa. Woovly will give Customer at least thirty (30) days' prior notice of any material change to this Addendum or to Annex 3 (Sub-processors), in accordance with Sections 5.7 and 12.2. Superseded versions are retained and made available on request.
This Data Protection Addendum ("Addendum") is entered into between Woovly India Pvt Ltd, a company incorporated under the laws of India having its registered office at Flat No. 001, Ground Floor, HM Delphi, 7th C Main, 3rd Block, Koramangala, Bengaluru, Karnataka, 560068, India, operating the Services under the brand "Live2.ai" ("Woovly"), and the Customer (as defined in the Agreement) ("Customer"). It forms part of the Woovly India Pvt Ltd Terms of Use set forth at https://live2.ai/legal/terms-of-use, or such other written or electronic agreement incorporating this Addendum, in each case governing Customer's access to and use of the Services (the "Agreement").
Customer enters into this Addendum on behalf of itself and any Affiliates authorised to use the Services under the Agreement and which have not entered into a separate contractual arrangement with Woovly. For the purposes of this Addendum only, and except where otherwise indicated, references to "Customer" include Customer and such Affiliates.
The Parties agree that the terms set out below are added as an Addendum to the Agreement.
In this Addendum, the following terms have the meanings set out below, and cognate terms are construed accordingly:
"Affiliate" means an entity that owns or controls, is owned or controlled by, or is under common control or ownership with either Customer or Woovly (as the context allows), where control means the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
"AI Provider" means a Sub-processor that supplies foundation models, large language models, vision models, speech models or other machine-learning inference services used by Woovly in the provision of the Services. AI Providers in use are identified in Part B of Annex 3.
"Business day" means a day other than a Saturday, Sunday or public holiday in Bengaluru, India.
"Customer Content" means the social media posts, captions, images, video, audio, creative assets, comments, metadata and other material ingested into, generated by, uploaded to or published through the Services by or on behalf of Customer, including material ingested from Customer's connected social media accounts and from publicly accessible social media accounts that Customer configures the Services to monitor.
"Customer Personal Data" means any Personal Data provided or made available by Customer to Woovly, or collected by Woovly on behalf of Customer, which is Processed by Woovly to perform the Services, including Personal Data contained within Customer Content and Derived Data.
"Data Protection Laws" means all laws and regulations regarding the Processing of Personal Data applicable to either Party in connection with the Services, including without limitation: (a) the DPDP Act and the DPDP Rules; (b) EU Area Law; (c) US State Privacy Laws; and (d) any other applicable privacy, security or data protection law, in each case as amended, replaced or superseded from time to time.
"Derived Data" means audit findings, compliance scores, sentiment and other outputs that the Services generate about an identifiable individual.
"DPDP Act" means the Digital Personal Data Protection Act, 2023 (India), as amended from time to time.
"DPDP Rules" means the Digital Personal Data Protection Rules, 2025 (India), notified on 13 November 2025, as amended from time to time, together with any standards, directions or orders issued thereunder.
"Data Principal", "Data Fiduciary", "Data Processor", "Significant Data Fiduciary" and "Consent Manager" have the meanings given to them in the DPDP Act, and "Board" means the Data Protection Board of India.
"Effective Date" means the date on which Customer first accepts the Agreement, or an Order Form incorporating this Addendum, or, for any later version of this Addendum, the date on which that version takes effect under Section 12.2.
"EU Area" means the European Union, the European Economic Area, the United Kingdom, and Switzerland.
"EU Area Law" means (i) Regulation (EU) 2016/679 ("EU GDPR") together with applicable legislation implementing or supplementing the same; (ii) the UK GDPR, as defined in section 3(10) of the Data Protection Act 2018 of the United Kingdom, together with that Act; (iii) the Swiss Federal Act on Data Protection of 25 September 2020, in force from 1 September 2023, and its implementing Ordinance ("Swiss FADP"); (iv) any other data protection, security or privacy law applying in the EU Area; and (v) any successor or amendment to any of the foregoing.
"EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission by Implementing Decision (EU) 2021/914 of 4 June 2021, and any successor clauses.
"Notice address" means the email address that Customer designates for notices in its Order Form or in its account settings on the Services.
"Order Form" means an "Order" as defined in the Agreement, or any ordering document signed by the Parties that references this Addendum.
"Restricted Transfer" means: (a) where the EU GDPR applies, a transfer of Personal Data from the European Economic Area to a Third Country; (b) where the UK GDPR applies, a transfer of Personal Data from the United Kingdom to a Third Country; and (c) where the Swiss FADP applies, a transfer of Personal Data from Switzerland to a Third Country; in each case where such transfer would be prohibited in the absence of an appropriate transfer mechanism.
"Security Incident" and "Personal Data Breach" mean a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, and include a "personal data breach" as defined in the DPDP Act. They exclude unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked log-in attempts and denial-of-service attacks that do not result in unauthorised access to or loss of Customer Personal Data.
"Services" means the services supplied by Woovly to Customer or Customer's Affiliates pursuant to the Agreement, as described in Annex 1.
"Sub-processor" means any third party engaged by Woovly to Process Customer Personal Data in the provision of the Services.
"Third Country" means a country or territory that has not received an adequacy decision from the relevant authority (including the European Commission, the UK Secretary of State or the UK Information Commissioner's Office ("UK ICO"), or the Swiss Federal Data Protection and Information Commissioner ("Swiss FDPIC")) in respect of cross-border transfers of Personal Data.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK ICO under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.
"US State Privacy Laws" means the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and its implementing regulations, and any other US state comprehensive privacy law applicable to the Processing.
The terms "Business", "Business Purpose", "commercial purpose", "Contractor", "Controller", "Data Subject", "Personal Data", "Process", "Processor", "Sell", "Service Provider", "Share", "Supervisory Authority" and "Third Party" have the meanings given in the applicable Data Protection Laws.
Capitalised terms not otherwise defined in this Addendum have the meanings given to them in the Agreement.
2.1 Standard allocation. With regard to the Processing of Customer Personal Data, and as more fully described in Annex 1:
| Legal regime | Customer | Woovly |
|---|---|---|
| EU GDPR / UK GDPR / Swiss FADP | Controller | Processor |
| DPDP Act (India) | Data Fiduciary | Data Processor |
| CCPA and US State Privacy Laws | Business | Service Provider |
2.2 Customer as processor. Where Customer itself acts as a Processor or Data Processor on behalf of a third-party controller or Data Fiduciary (for example, where Customer is an agency acting for a brand), Woovly acts as a Sub-processor. In that case: (a) Customer warrants that it has the authority of the relevant controller or Data Fiduciary to enter into this Addendum and to issue the instructions given under it; and (b) Module Three of the EU SCCs applies to Restricted Transfers in place of Module Two, as set out in Section 8.2.
2.3 Woovly as Data Fiduciary for its own purposes. Woovly acts as an independent Controller and Data Fiduciary in respect of a limited category of data that it Processes for its own purposes, namely: account administration and billing contact details of Customer's users; security logs relating to access to and the security of Woovly's own systems; and aggregated, de-identified service statistics under Section 5.2(d). Woovly's processing of that data is governed by the Woovly Privacy Policy and not by this Addendum. Woovly does not act as a Controller or Data Fiduciary in respect of Customer Content or Derived Data. Records of the Processing of Customer Personal Data that Woovly retains under Section 9.8 are retained on Customer's behalf.
2.4 Customer communications. Customer is solely responsible for timely communications to its Affiliates and to any relevant controller or Data Fiduciary receiving the Services, where such communications are required to enable them to comply with Data Protection Laws.
3.1 Annex 1 sets out the Parties' agreed understanding of the subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subjects and Data Principals in respect of the Processing carried out under this Addendum. The Parties may amend Annex 1 by mutual written agreement.
3.2 The purpose of Processing under this Addendum is the provision of the Services pursuant to the Agreement and any Order Form(s), and no other purpose.
3.3 Publicly available content. The Parties acknowledge that a substantial portion of Customer Content consists of material that the relevant individual has themselves published to a publicly accessible social media profile. Where such material constitutes personal data made publicly available by the Data Principal to whom it relates, Section 3(c)(ii)(A) of the DPDP Act provides that the DPDP Act does not apply to it. The exemption does not extend to: (a) Personal Data within that material which relates to a person other than the one who published it (for example, a third person appearing in a creator's video, or an individual featured in a brand's post); (b) Derived Data, which the individual has not made publicly available; or (c) material that is no longer publicly available at source. Customer remains responsible under Section 4.1 for the lawful basis for Processing that data. Notwithstanding the exemption, Woovly applies the security, retention, deletion, sub-processor and no-training safeguards in this Addendum to all Customer Personal Data, including publicly available content. Nothing in this Section 3.3 limits the application of EU Area Law, which contains no equivalent exemption.
3.4 Monitored accounts of individuals in India. For each account of an individual in India that Customer configures the Services to monitor, Customer warrants that it holds the Data Principal's consent under Section 6 of the DPDP Act, or another ground under Section 4 of the DPDP Act, for the Processing of Derived Data about that individual. Where Customer holds no such ground (for example, for an individual's account used only for competitive or category benchmarking), Customer shall use only aggregate benchmarking outputs that do not identify that individual.
3.5 Content removed at source. Where Woovly becomes aware, including through a refresh of the source, that material ingested from a publicly accessible account is no longer publicly available at source, Woovly shall erase that material within thirty (30) days, unless Customer has another lawful basis for retaining it and has told Woovly so in writing.
3.6 Commencement of the DPDP Act and DPDP Rules. The DPDP Act and the DPDP Rules come into force in phases, as notified by the Central Government and as set out in Rule 1 of the DPDP Rules. Woovly shall perform each obligation in this Addendum that refers to the DPDP Act or the DPDP Rules from the Effective Date, whether or not the relevant provision has yet come into force, except for Section 9.8 and any other obligation to retain Personal Data contrary to Customer's deletion instruction, which applies only from the date on which Rule 8(3) of the DPDP Rules comes into force.
4.1 Customer shall comply with all applicable Data Protection Laws in connection with this Addendum and the Processing of Customer Personal Data. As between the Parties, Customer is solely responsible for: (a) the lawfulness of its collection of, and transfer to Woovly of, Customer Personal Data; (b) issuing notices meeting Rule 3 of the DPDP Rules and, where required, obtaining and managing consents under Sections 5 and 6 of the DPDP Act, or relying on a legitimate use under Section 7 of the DPDP Act or a lawful basis under EU Area Law; (c) providing all notices required by Articles 13 and 14 of the EU GDPR and by the CCPA, including to individuals whose publicly available content Customer configures the Services to ingest; (d) obtaining any consent required under Article 5(3) of Directive 2002/58/EC, or equivalent law, for technologies deployed by Live2.ai components on Customer's websites and applications; (e) the accuracy and quality of Customer Personal Data; and (f) ensuring that its instructions to Woovly comply with Data Protection Laws.
4.2 Instructions. The Agreement, this Addendum, the applicable Order Form(s), and Customer's configuration and use of the Services' features and functionality constitute Customer's complete documented instructions to Woovly in relation to the Processing of Customer Personal Data. Any additional or alternative instruction must be agreed in writing and may be subject to additional charges.
4.3 Prohibited data. Customer shall not submit to the Services, or configure the Services to collect or target: (a) data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation (Article 9 EU GDPR); (b) financial account numbers, government identification numbers, or payment card data; (c) data relating to criminal convictions and offences; or (d) the personal data of children or of persons with disabilities who have a lawful guardian (see Section 7).
4.4 Incidental content. Customer acknowledges that published social media content may incidentally contain or reveal categories of data described in Section 4.3(a) — for example, an image in which a person's apparent ethnicity or religious dress is visible. Woovly does not intentionally Process, derive, infer, classify or index such categories, and does not operate any feature that identifies individuals by such characteristics. Customer shall not configure the Services, or use their outputs, to identify, segment, score or target individuals on the basis of any such characteristic.
4.5 Platform terms. Customer is responsible for ensuring that its connection of social media accounts to the Services, and its configuration of monitored accounts, complies with the terms of the relevant social media platforms and with Data Protection Laws.
4.6 Significant Data Fiduciary status. Customer shall notify Woovly in writing within thirty (30) days of being notified, or of falling within a class notified, as a Significant Data Fiduciary under Section 10 of the DPDP Act, so that Woovly can provide the assistance described in Sections 5.11, 5.13(c) and 8.1(d).
Woovly shall comply with all applicable Data Protection Laws in its Processing of Customer Personal Data, and shall:
5.1 Purpose limitation. Process Customer Personal Data only for the purposes of the Agreement and the specific purposes set out in Annex 1, and otherwise solely on the documented instructions of Customer. Woovly shall not Sell or Share Customer Personal Data, and shall not use, retain, disclose or otherwise Process Customer Personal Data outside the direct business relationship with Customer, or for any other purpose including any commercial purpose of Woovly, except as required by law.
5.2 Permitted ancillary processing. Notwithstanding Section 5.1, Woovly may Process Customer Personal Data to the extent strictly necessary to: (a) operate, secure, maintain and provide technical support for the Services; (b) detect, prevent and respond to Security Incidents, fraud, abuse or unlawful activity; (c) comply with a legally binding request under Section 5.9; and (d) produce aggregated and de-identified statistics about the operation of the Services, provided that such statistics cannot be used, alone or in combination, to identify or re-identify any individual, device, or Customer. Woovly shall not attempt to re-identify such statistics and shall contractually prohibit any recipient from doing so. Woovly shall not use Customer Personal Data to develop, improve or enhance products or services for any other customer or for its own general commercial benefit.
5.3 No use for model training. This Section 5.3 is a material term of this Addendum.
(a) Woovly shall not use Customer Personal Data or Customer Content to train, fine-tune or otherwise modify the weights of any machine-learning model, whether owned by Woovly or by any third party, or to develop or improve any model that is made available to anyone other than Customer. Testing and monitoring the performance of the Services provided to Customer, and creating Customer-specific embeddings, indices, prompts and configurations used only to provide the Services to Customer, are permitted.
(b) Woovly shall contractually prohibit each AI Provider from using Customer Personal Data or Customer Content for model training or model improvement, and shall enable zero-retention and no-training configurations wherever the AI Provider makes them available. The current position for each AI Provider is stated in Part B of Annex 3.
(c) Woovly shall ensure that no AI Provider subjects Customer Personal Data or Customer Content to human review, except as strictly necessary to investigate abuse or a Security Incident, or to comply with law, and subject to confidentiality obligations no less protective than those in Section 5.5.
(d) Woovly does not enter into arrangements with AI Providers that operate on the basis of shared or pooled customer data. Woovly contracts with each AI Provider under its own enterprise data processing terms.
(e) Nothing in this Section 5.3 prevents Woovly from using aggregated, de-identified statistics as permitted by Section 5.2(d), or from training models exclusively on data that contains no Customer Personal Data or Customer Content.
5.4 Automated decision-making and human oversight.
(a) The outputs of the Services are analytical and advisory in nature and are designed to be reviewed and acted on by Customer's personnel. Woovly does not use the Services to make any decision based solely on automated processing that produces legal effects concerning a Data Subject or similarly significantly affects a Data Subject within the meaning of Article 22 of the EU GDPR.
(b) Customer shall not use any output of the Services as the sole or determining basis for a decision that produces legal or similarly significant effects on a Data Subject or Data Principal (including the payment, selection, renewal or termination of a creator) without meaningful human review. Where Customer does so, Customer is responsible for the safeguards required by Article 22(2) and 22(3) of the EU GDPR and equivalent law, and Woovly shall provide information about the logic involved under Section 5.11.
(c) Woovly shall, on request, disclose the known limitations and error rates of the Services' outputs, and shall correct or erase Derived Data on Customer's instruction, to enable Customer's compliance with Sections 8(3) and 12 of the DPDP Act and Article 16 of the EU GDPR.
(d) Customer is responsible for any decision it takes on the basis of the Services' outputs.
5.5 Confidentiality. Ensure that Woovly personnel authorised to Process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory obligation of confidentiality, are subject to appropriate background screening to the extent permitted by applicable law, receive privacy and security training, and Process Customer Personal Data only on authorisation and on a need-to-know basis.
5.6 Security. Implement and maintain the technical and organisational measures set out in Annex 2, and, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing as well as the risks to the rights and freedoms of natural persons, implement and maintain such further appropriate administrative, technical and organisational measures as are required to ensure a level of security appropriate to the risk, in accordance with Article 32 of the EU GDPR and Rule 6 of the DPDP Rules. Woovly shall not materially degrade the measures set out in Annex 2 during the term of the Agreement. The Parties agree that this Section 5.6 and Annex 2 are the contractual provision for reasonable security safeguards between Data Fiduciary and Data Processor required by Rule 6(1)(f) of the DPDP Rules.
5.7 Sub-processors. Customer grants Woovly general authorisation to engage Sub-processors, and specific authorisation for the Sub-processors listed in Annex 3, subject to Woovly:
(a) giving Customer at least thirty (30) days' prior notice of any intended addition or replacement of a Sub-processor, by email to Customer's notice address and by updating Annex 3;
(b) imposing on each Sub-processor, by written contract, data protection obligations that provide at least the protection required by Article 28(3) of the EU GDPR and Rule 6 of the DPDP Rules and, for AI Providers, the restrictions in Sections 5.3(a) and 5.3(b), in each case as appropriate to the services the Sub-processor provides; and
(c) remaining fully liable to Customer for the performance of each Sub-processor's data protection obligations, subject to Section 10.5.
(d) Objection. Customer may object to a proposed Sub-processor on reasonable data protection grounds within thirty (30) days of notice. The Parties shall then work in good faith for up to thirty (30) days to find a commercially reasonable alternative. If no solution is found, either Party may terminate the affected Services on written notice, without damages, penalty or indemnification. Notwithstanding anything in the Agreement, Woovly shall then refund the pro-rata portion of any fees prepaid for the terminated Services that covers the period after termination.
(e) Emergency replacement. Where a Sub-processor must be replaced urgently for security or continuity reasons, Woovly may do so with shorter notice, provided it informs Customer as soon as possible and Customer retains the objection right in Section 5.7(d).
(f) No onward disclosure. Woovly shall not disclose Customer Personal Data to any data broker, data enrichment provider, advertising network, or other third party not listed in Annex 3.
5.8 No combining or enrichment. Woovly shall not combine Customer Personal Data that it Processes on Customer's behalf with Personal Data received from or on behalf of any other person, or collected from Woovly's own interaction with individuals, except where strictly necessary to perform the Services for Customer. Woovly shall not enrich, append to, or augment Customer Personal Data using third-party data sources.
5.9 Legally binding requests. To the extent legally permissible, promptly notify Customer of any legally binding request for disclosure of Customer Personal Data by a law enforcement authority, court or government agency, and shall: (a) challenge any request that is not legally valid; (b) disclose only the minimum data legally required; (c) not disclose Customer Personal Data in response to a request that is not legally binding, and notify Customer of the rejection; and (d) maintain a record of all such requests and make it available to Customer on request. Where Woovly is prohibited from notifying Customer, it shall use reasonable efforts to obtain a waiver of the prohibition.
(e) Requisitions under the DPDP Act. Where Customer receives a requisition for information from the Board, or from the Central Government under Section 36 of the DPDP Act and Rule 23 of the DPDP Rules, Woovly shall provide the information in its possession that Customer reasonably requires, in time to allow Customer to comply within the period specified. Where Woovly itself receives such a requisition with a direction under Rule 23(2) not to disclose it, Woovly shall comply with that direction and shall notify Customer as soon as, and to the extent that, it is permitted to do so.
5.10 Personal Data Breach. Woovly shall, upon becoming aware of a Personal Data Breach affecting Customer Personal Data:
(a) notify Customer without undue delay and in any event within twenty-four (24) hours of becoming aware, so as to enable Customer, as Data Fiduciary, to meet its obligations under Rule 7 of the DPDP Rules to intimate the Board and each affected Data Principal without delay and to furnish a detailed report to the Board within seventy-two (72) hours, and its obligation under Article 33 of the EU GDPR to notify the competent Supervisory Authority within seventy-two (72) hours;
(b) include in that notification, to the extent then available, and supplement it in phases as further information becomes available: (i) a description of the nature, extent and timing of the breach and the location at which it occurred, and its likely impact; (ii) the categories and approximate number of Data Principals and Data Subjects and of records affected; (iii) the likely consequences of the breach; (iv) the broad facts relating to the events, circumstances and reasons leading to the breach; (v) the measures taken and proposed to mitigate risk; (vi) the remedial measures taken to prevent recurrence; (vii) Woovly's findings regarding the person or cause that gave rise to the breach; and (viii) the name and contact details of Woovly's contact point;
(c) provide, on Customer's request, the information required for Customer to make an intimation to affected Data Principals under Rule 7 of the DPDP Rules, in clear and plain language, including a description of the breach, its consequences relevant to the Data Principal, the safeguards implemented, and the safety measures the Data Principal may take;
(d) take reasonable measures to investigate, contain, remediate and mitigate the effects of the breach, preserve forensic evidence, and keep Customer reasonably and regularly informed; and
(e) not make any public statement or notification identifying Customer in connection with the breach without Customer's prior written consent, unless legally required.
Woovly shall also report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the time required by its directions under Section 70B of the Information Technology Act, 2000, and shall inform Customer that it has done so.
Woovly's notification under this Section 5.10 is not, and shall not be construed as, an acknowledgement of fault or liability.
5.11 Assistance with impact assessments. Provide reasonable assistance to Customer with its obligations under Articles 32 to 36 of the EU GDPR and, where Customer is a Significant Data Fiduciary, under Section 10 of the DPDP Act and Rule 13 of the DPDP Rules, taking into account the nature of the Processing and the information available to Woovly. That assistance includes supporting Customer's annual Data Protection Impact Assessment and audit under Rule 13(1). It also includes giving Customer the documentation it reasonably requires, about the models, algorithmic software and data flows used in the Services, to carry out the due diligence required by Rule 13(3) and verify that they are not likely to pose a risk to the rights of Data Principals. Woovly is not required to disclose source code, model weights, prompts or other trade secrets, and documentation provided under this Section 5.11 is Woovly's Confidential Information. Assistance under Articles 35 and 36 of the EU GDPR may be subject to reasonable charges where it materially exceeds the provision of standard documentation.
5.12 Records. Maintain written records of its Processing activities carried out on behalf of Customer sufficient to demonstrate compliance with this Addendum, Article 30(2) of the EU GDPR and Section 8 of the DPDP Act, and make them available to Customer on request.
5.13 Audit. Make available to Customer all information reasonably necessary to demonstrate compliance with this Addendum, and allow for and contribute to audits, including inspections, conducted by Customer or an independent third-party auditor mandated by Customer and reasonably acceptable to Woovly, subject to the auditor being bound by confidentiality obligations. An auditor that is a competitor of Woovly is not reasonably acceptable.
(a) In the first instance, Woovly shall satisfy audit requests by providing its current certifications, third-party assessment reports, penetration test summaries, and completed responses to Customer's security and privacy questionnaires. Only where Customer cannot reasonably establish compliance from that material may Customer request an on-site or systems inspection.
(b) Inspections shall take place no more than once per twelve (12) month period, on at least thirty (30) days' prior written notice, during Woovly's normal business hours, and in a manner that minimises disruption. Each inspection is limited to two (2) business days, and excludes other customers' data and Sub-processor facilities (for which Woovly shall provide the Sub-processor's own audit reports). Customer shall bear its own costs. Woovly shall bear its own costs for the first inspection in any twelve-month period and for inspections under Section 5.13(c); Customer shall reimburse Woovly's reasonable costs of any other inspection.
(c) The frequency and cost limitations in Section 5.13(b) do not apply where an audit is required by the instruction of a competent Supervisory Authority or the Board, or where Customer reasonably believes a further audit is necessary following a Personal Data Breach affecting Customer Personal Data, or where an audit of Woovly is reasonably required for Customer's annual audit as a Significant Data Fiduciary under Rule 13(1) of the DPDP Rules. In those cases Woovly shall bear its own costs of cooperation.
5.14 Notification of inability to comply. Immediately inform Customer if Woovly determines that it can no longer meet its obligations under Data Protection Laws or this Addendum, or if in Woovly's opinion an instruction from Customer infringes Data Protection Laws. In such case Woovly may suspend the affected Processing until the instruction is confirmed, withdrawn or amended. Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Customer Personal Data.
6.1 Assistance. Taking into account the nature of the Processing, Woovly shall assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects and Data Principals to exercise their rights, including:
| Right | EU Area Law | DPDP Act |
|---|---|---|
| Access to information about processing | Art. 15 | S. 11 |
| Identities of other Data Fiduciaries and Data Processors with whom data is shared | Art. 15(1)(c) | S. 11(1)(b) |
| Correction / rectification | Art. 16 | S. 12 |
| Erasure | Art. 17 | S. 12 |
| Restriction of processing | Art. 18 | — |
| Data portability | Art. 20 | — |
| Objection | Art. 21 | — |
| Grievance redressal by the Data Fiduciary | — | S. 8(10), S. 13 |
| Complaint to a regulator | Art. 77 | S. 13(3) |
| Nomination (to exercise rights on death or incapacity) | — | S. 14 |
6.2 Self-service. The Services provide functionality enabling Customer to access, export, correct and delete Customer Personal Data directly. Customer shall use that functionality in the first instance. Where Customer cannot fulfil a request using the Services, Woovly shall provide assistance within fifteen (15) days of Customer's written request, so that Customer can respond within the periods that apply to it under Data Protection Laws, including the grievance redressal period it publishes under Rule 14(3) of the DPDP Rules. For requests under Section 11(1)(b) of the DPDP Act, Woovly shall identify the Sub-processors in Annex 3 that have Processed the relevant Data Principal's data and describe the data so shared. Woovly shall not charge Customer for such assistance where it does not materially exceed the effort of a standard request.
6.3 Forwarding requests. Woovly shall, to the extent legally permissible, promptly and in any event within five (5) business days notify Customer of any communication it receives directly from a Data Subject or Data Principal relating to Customer Personal Data, or from a Supervisory Authority or the Board. Woovly shall not respond to any such communication except to acknowledge receipt and direct the individual to Customer, unless Customer authorises it to respond or applicable law requires a response.
6.4 Nomination. Woovly shall support Customer in giving effect to a nomination made under Section 14 of the DPDP Act by treating a validated instruction from a nominee, forwarded by Customer, as an instruction relating to the relevant Data Principal.
6.5 Consent withdrawal. Where Customer notifies Woovly that a Data Principal has withdrawn consent under Section 6(4) of the DPDP Act, or that a lawful basis has otherwise ceased, Woovly shall cease the relevant Processing without undue delay and erase the relevant Customer Personal Data, and cause its Sub-processors to erase it, within thirty (30) days, in accordance with Section 6(6) and Section 8(7) of the DPDP Act, except to the extent retention is required by law, including under Section 9.8.
6.6 Consent Managers. Where Customer uses a registered Consent Manager under Section 6(7) of the DPDP Act and Rule 4 of the DPDP Rules, Woovly shall accept and give effect to consent and withdrawal signals transmitted to it by Customer from that Consent Manager, in the same manner as a direct instruction from Customer.
6.7 Grievance redressal and contacts. Pursuant to Sections 8(9) and 8(10) of the DPDP Act and Rules 9 and 14 of the DPDP Rules, Woovly publishes the following contacts. Woovly has voluntarily appointed a Data Protection Officer, who is the person able to answer questions on Woovly's behalf under Section 8(9). Woovly shall acknowledge any communication received at these addresses within three (3) business days and provide a substantive response within thirty (30) days, save that communications relating to Customer Personal Data are handled under Section 6.3.
| Role | Name | Contact |
|---|---|---|
| Data Protection Officer | Yash Arora | dpo@live2.ai |
| Grievance Officer (India) | Yash Arora | grievance@live2.ai |
| Security incident reporting | Security Team | security@live2.ai |
Woovly's Data Protection Officer and Grievance Officer are based in India.
6.8 Records of notice and consent. Where the Services capture a notice or consent on Customer's behalf (for example, through a registration component embedded on Customer's website), Woovly shall keep a tamper-evident record of the version of the notice shown, the consent given or withdrawn, and the time it was given or withdrawn, and shall provide that record to Customer on request so that Customer can meet its obligation under Section 6(10) of the DPDP Act.
7.1 The Services are not directed at, and are not intended for use by, children. Woovly does not knowingly Process the Personal Data of a child (a person under eighteen (18) years of age under the DPDP Act, or the applicable age of digital consent under EU Area Law).
7.2 Woovly shall not, in the provision of the Services: (a) undertake tracking or behavioural monitoring of children; (b) serve targeted advertising directed at children; or (c) operate any feature that infers, estimates or classifies the age of an individual, in accordance with Section 9(3) of the DPDP Act.
7.3 Customer shall not submit to the Services, or configure the Services to collect or target, the Personal Data of children or of persons with disabilities who have a lawful guardian. Customer shall not configure the Services to monitor any account that it knows, or has reason to believe, is operated by a child, and shall notify Woovly of any such account so that it can be suppressed. Verifiable consent obtained under Section 9(1) of the DPDP Act and Rules 10 and 11 of the DPDP Rules does not permit processing that Section 9(3) prohibits.
7.4 Where either Party becomes aware that the Personal Data of a child has been Processed without a valid basis, it shall notify the other without undue delay, and Woovly shall erase that data within thirty (30) days of Customer's instruction.
(a) Woovly Processes Customer Personal Data primarily in India. Certain Sub-processors listed in Annex 3 Process Customer Personal Data outside India; the location of each Sub-processor is stated in Annex 3.
(b) Woovly shall comply with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, and shall meet any requirement that the Central Government may specify by general or special order in respect of making Personal Data available to a foreign State, or to any person or entity under the control of or any agency of such a State.
(c) Woovly shall not transfer Customer Personal Data to any country or territory in respect of which the Central Government has notified a restriction under Section 16 of the DPDP Act. Woovly shall monitor such notifications and, if a Sub-processor location becomes restricted, shall notify Customer within fifteen (15) days and migrate the affected Processing to a permitted location, or to India, within a reasonable period agreed with Customer.
(d) Significant Data Fiduciary localisation. Where Customer is notified as a Significant Data Fiduciary and Rule 13(4) of the DPDP Rules requires that specified classes of Personal Data and traffic data pertaining to their flow are not transferred outside India, Woovly shall, on Customer's written notice, configure the Services so that such data is Processed and stored solely within India, to the extent technically available. As at the date of this version of the Addendum, hosting, storage, databases, backups and all self-hosted perception models (vision, demographic inference, speech-to-text and optical character recognition) operate wholly within India and can be configured as India-only. Large language model inference is performed by the AI Provider listed at Annex 3 Part B row A1, which Processes derived textual signals outside India under the configuration stated in Annex 3; where a Customer requires strict India-only Processing, Woovly will on written notice disable the affected analytical features or agree a substitute in-region model with Customer.
(e) Woovly shall not transfer Customer Personal Data to any jurisdiction, or engage any Sub-processor, in a manner that would cause Customer to breach Section 16 of the DPDP Act.
Where a transfer of Customer Personal Data from Customer or its Affiliates (as data exporter) to Woovly (as data importer) is a Restricted Transfer, the following apply and are incorporated into and form part of this Addendum:
(a) EU GDPR. The EU SCCs apply, completed as follows:
(i) Module Two (controller to processor) applies where Customer acts as Controller. Module Three (processor to processor) applies where Customer acts as Processor, as contemplated by Section 2.2.
(ii) In Clause 7, the optional docking clause applies.
(iii) In Clause 9, Option 2 (general written authorisation) applies, and the time period for prior notice of Sub-processor changes is thirty (30) days, as set out in Section 5.7(a).
(iv) In Clause 11, the optional independent dispute resolution language does not apply.
(v) In Clause 13 and Annex I.C, the competent Supervisory Authority is the supervisory authority of the EU Member State in which Customer, as data exporter, is established. Where Customer is not established in the EU but has appointed a representative under Article 27 of the EU GDPR, it is the supervisory authority of the Member State in which that representative is established. Where Customer is neither established in the EU nor represented, it is the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located, and in the absence of any such determination, the Irish Data Protection Commission.
(vi) In Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland.
(vii) In Clause 18(b), disputes shall be resolved before the courts of Ireland.
(viii) Annex I of the EU SCCs is deemed completed with the information in Annex 1 to this Addendum.
(ix) Annex II of the EU SCCs is deemed completed with the information in Annex 2 to this Addendum.
(x) Annex III of the EU SCCs (where applicable) is deemed completed with the information in Annex 3 to this Addendum.
(b) Swiss FADP. The EU SCCs apply as set out in Section 8.2(a), with the following modifications:
(i) references to "Regulation (EU) 2016/679" are interpreted as references to the Swiss FADP and the equivalent provisions therein;
(ii) references to "EU", "Union", "Member State" and "Member State law" are interpreted as references to Switzerland and Swiss law;
(iii) the competent supervisory authority is the Swiss FDPIC, and references to "competent courts" are interpreted as references to the competent courts of Switzerland;
(iv) the EU SCCs as so modified are governed by the laws of Switzerland and disputes shall be resolved before the competent Swiss courts; and
(v) where the transfer is subject to both the EU GDPR and the Swiss FADP, the EU SCCs apply in their unmodified form in respect of the EU GDPR element and as modified by this Section 8.2(b) in respect of the Swiss FADP element.
(c) UK GDPR. The EU SCCs apply as set out in Section 8.2(a), as modified and interpreted by Part 2: Mandatory Clauses of the UK Addendum, which is incorporated into and forms an integral part of this Addendum. Any conflict between the EU SCCs and the UK Addendum is resolved in accordance with sections 10 and 11 of the UK Addendum. In Part 1 of the UK Addendum: Table 1 is completed with the information in Annex 1 Part A and the acceptance record under Section 12.3; Table 2 is completed by the selections in Section 8.2(a); Table 3 is completed with the information in Annexes 1, 2 and 3; and Table 4 is completed by selecting both "Importer" and "Exporter". The UK Addendum is governed by the laws of England and Wales and disputes shall be resolved before the courts of England and Wales.
(d) Woovly shall not participate in any other Restricted Transfer of Customer Personal Data, whether as importer or exporter, unless it is made in compliance with applicable Data Protection Laws and pursuant to an appropriate transfer mechanism.
(e) Transfer impact. Woovly shall, on request, provide Customer with the information reasonably necessary for Customer to carry out a transfer impact assessment, including information about the legal regime applicable to Woovly and its Sub-processors in each Third Country and about government access requests received.
(f) Woovly as Controller. Module One (controller to controller) of the EU SCCs, completed as set out in Section 8.2(a) to the extent applicable, applies to any Restricted Transfer to Woovly of Personal Data that Woovly Processes as an independent Controller under Section 2.3.
9.1 Woovly shall cease Processing Customer Personal Data on the termination or expiry of the Agreement, and shall, at Customer's election notified within thirty (30) days of termination, return or delete all copies of Customer Personal Data.
9.2 Deletion timetable. Unless Customer elects return, Woovly shall delete Customer Personal Data:
| Environment | Deletion deadline |
|---|---|
| Production systems and databases | Within thirty (30) days of termination or of Customer's written instruction |
| Sub-processor systems | Within forty-five (45) days |
| Backups and archives | Within ninety (90) days, on expiry of the rolling backup cycle |
Customer Personal Data held in backups is not restored or otherwise Processed during that period other than for disaster recovery, and remains subject to this Addendum until deleted. This timetable is subject to Section 9.8.
9.3 Export. Woovly shall make Customer Personal Data available for export in a structured, commonly used, machine-readable format for a period of thirty (30) days following termination, at no additional charge.
9.4 Certification. Woovly shall provide written certification of deletion within fifteen (15) days of Customer's request.
9.5 Legal retention. Woovly may retain Customer Personal Data to the extent and for the period required by applicable law, including retention of financial and tax records. Any data so retained remains subject to the confidentiality, security and no-training obligations of this Addendum and is Processed for no purpose other than compliance with that legal requirement.
9.6 Interim erasure. Woovly shall erase Customer Personal Data during the term on Customer's written instruction, including where required to give effect to Section 6.5 or Section 8(7) of the DPDP Act, within thirty (30) days, and shall support Customer in giving any advance intimation to Data Principals required by Rule 8(2) of the DPDP Rules.
9.7 Third Schedule. Where Customer is a Data Fiduciary of a class specified in the Third Schedule to the DPDP Rules, Customer shall notify Woovly, and Woovly shall then apply the erasure period in that Schedule to Customer Personal Data relating to the relevant user accounts and support the intimation required by Rule 8(2) of the DPDP Rules. Retention periods otherwise applicable to the Services are set out in Annex 1.
9.8 Minimum retention of processing records. Rule 8(3) of the DPDP Rules requires a Data Fiduciary to retain the Personal Data, associated traffic data and other logs of each processing activity, including processing carried out on its behalf by a Data Processor, for at least one (1) year from the date of that processing.
(a) Application. This Section 9.8 applies only from the date on which Rule 8(3) comes into force, and only where Customer is established in India or has confirmed to Woovly in writing that Rule 8(3) applies to it. Where it does not apply, Sections 6.5, 9.2 and 9.6 apply without modification.
(b) Exclusions. This Section 9.8 does not apply to Personal Data within Section 3(c)(ii) or Section 17(1)(d) of the DPDP Act. For Personal Data subject to EU Area Law, it applies only as permitted by Clause 8.5 of the EU SCCs and Article 28(3)(g) of the EU GDPR.
(c) Retention. Where this Section 9.8 applies, and notwithstanding Sections 6.5, 9.2 and 9.6, Woovly shall retain those records on Customer's behalf until one (1) year after the date of the processing to which they relate. For this purpose, "date of processing" means the date of the last processing activity other than storage under this Section 9.8.
(d) Restricted use. Woovly shall hold those records in segregated, access-restricted storage and Process them only for the purposes specified in the Seventh Schedule to the DPDP Rules, to detect, investigate and remediate unauthorised access under Rule 6(1)(e) of the DPDP Rules, or as otherwise required by law.
(e) Erasure. Woovly shall erase those records within thirty (30) days after the one-year period ends, unless further retention is required by law.
Records retained under this Section 9.8 remain subject to this Addendum until erased.
10.1 Limitation. Each Party's liability arising out of or in connection with this Addendum, whether in contract, tort or any other theory of liability, is governed by this Section 10. Any exclusion of direct damages in the Agreement does not apply to this Addendum. Subject to Section 10.5, the other exclusions and limitations of liability in the Agreement apply.
10.2 Mutual indemnity. Each Party (the "Indemnifying Party") shall defend, indemnify and hold harmless the other Party and its Affiliates from and against losses, damages, settlements and reasonable costs and expenses (including reasonable legal fees) arising from a third-party claim (including a claim by a Data Subject or Data Principal) to the extent caused by the Indemnifying Party's breach of this Addendum. Fines or penalties imposed by a Supervisory Authority or the Board are recoverable under this Section 10.2 only to the extent that they are: (a) finally determined to be attributable to the Indemnifying Party's breach; (b) lawfully recoverable; and (c) not caused by the indemnified Party's failure to meet obligations imposed on it directly by Data Protection Laws.
10.3 Procedure. The indemnified Party shall promptly notify the Indemnifying Party of any claim, allow the Indemnifying Party to control the defence and settlement (provided that no settlement imposing a non-indemnified obligation on the indemnified Party is made without its consent), and provide reasonable cooperation at the Indemnifying Party's expense. The indemnified Party may participate in the defence with counsel of its own choosing at its own expense.
10.4 Statutory rights preserved. Nothing in this Section 10 limits or excludes either Party's liability to a Data Subject or Data Principal under Data Protection Laws, the EU SCCs or the UK Addendum.
10.5 Cap. Each Party's aggregate liability under or in connection with this Addendum (including under Sections 5.7(c) and 10.2 and, as between the Parties, Clause 12 of the EU SCCs) shall not exceed the lesser of (i) two (2) times the fees paid or payable by Customer under the Agreement in the twelve (12) months preceding the event giving rise to the claim, and (ii) INR 1 crore.
11.1 This Addendum supplements the Agreement. In the event of any inconsistency between this Addendum and the Agreement, this Addendum prevails in respect of the Processing of Customer Personal Data and the use of Customer Content.
11.2 In the event of any conflict between this Addendum and the EU SCCs or the UK Addendum, the EU SCCs or UK Addendum prevail.
11.3 In the event of any conflict between the general provisions of this Addendum and Section 8.1 (transfers out of India) or any other provision expressed to apply to the DPDP Act, the DPDP-specific provision prevails in respect of Processing subject to the DPDP Act.
12.1 Term and survival. This Addendum takes effect on the Effective Date. It survives termination or expiry of the Agreement for so long as Woovly or any Sub-processor retains Customer Personal Data, including under Sections 9.2, 9.5 and 9.8. Sections 5.3, 5.5, 9.4, 10, 11 and 12.5 survive thereafter.
12.2 Changes. Woovly may update this Addendum to reflect changes in Data Protection Laws or in the Services, on at least thirty (30) days' prior notice to Customer's notice address. Woovly shall identify in that notice any change it considers material. If Customer, acting reasonably, notifies Woovly within the notice period that an update materially reduces the protections afforded to Customer Personal Data, the prior version continues to apply to Customer until the Parties agree otherwise or Customer terminates the affected Services, in which case Woovly shall refund the pro-rata portion of any prepaid fees covering the period after termination. No update modifies the EU SCCs or the UK Addendum. Changes to Annex 3 are governed by Section 5.7.
12.3 Acceptance. This Addendum is accepted by Customer's execution of the Agreement or an Order Form incorporating it, or by Customer's acceptance of the Terms of Use through an affirmative act (such as ticking a box) that refers to this Addendum. Woovly records Customer's legal name and address, the name and email address of the individual who accepted, the version of this Addendum accepted and the time of acceptance. That record constitutes the data exporter's details and signature for Annex I.A of the EU SCCs and Table 1 of the UK Addendum. No other signature is required. Customer may request a countersigned copy by contacting the Data Protection Officer named in Section 6.7.
12.4 Severability. If any provision of this Addendum is held unlawful or unenforceable by a court or competent authority, that shall not invalidate or render unenforceable any other provision.
12.5 Governing law. Except as provided in Section 8.2 in respect of the EU SCCs and the UK Addendum, this Addendum is governed by the law stated in the Agreement. Nothing in this Section 12.5 limits the jurisdiction of the Board or of any competent Supervisory Authority.
12.6 Compliance programme. Woovly maintains a data protection programme that addresses: privacy by design and by default; security of Processing; notification of Personal Data Breaches to Customer in accordance with Section 5.10; support for data protection impact assessments and prior consultation with Supervisory Authorities and the Board where required; and personnel training. Woovly operates an information security management system as described in Annex 2.
This Annex completes Annex I of the EU SCCs and Tables 1 and 3 of Part 1 of the UK Addendum.
| Field | Detail |
|---|---|
| Name | Customer, as recorded under Section 12.3 or set out in the relevant Order Form |
| Address | As recorded under Section 12.3 or set out in the relevant Order Form |
| Contact person | As recorded under Section 12.3 or set out in the relevant Order Form |
| Activities relevant to the data transferred | Recipient of the Services provided by Woovly under the Agreement |
| Signature and date | The acceptance record under Section 12.3, or the signature on the Agreement or Order Form |
| Role | Controller / Data Fiduciary; or Processor / Data Processor where Section 2.2 applies |
| Field | Detail |
|---|---|
| Name | Woovly India Pvt Ltd (operating as Live2.ai) |
| Address | Flat No. 001, Ground Floor, HM Delphi, 7th C Main, 3rd Block, Koramangala, Bengaluru, Karnataka, 560068, India |
| Contact person | Yash Arora, Data Protection Officer, dpo@live2.ai |
| Activities relevant to the data transferred | Provision of the Services to Customer under the Agreement, as described in Part C below |
| Signature and date | As set out in the Agreement |
| Role | Processor / Data Processor |
Determined in accordance with Section 8.2(a)(v) of this Addendum.
| Category | Data elements |
|---|---|
| Tenant user data | Name, business email address and role of Customer's authorised users, and their activity within Customer's tenant (such as content reviewed, findings actioned and reports generated) |
| Social profile data | Platform username / handle, display name, profile picture, biography text, platform user ID, publicly stated location, public follower and following counts, account verification status |
| Content data | Published posts, captions, hashtags, images, video, audio, thumbnails, product tags, links, and any Personal Data appearing within that content |
| Engagement data | Publicly visible comment and reply text with author handle, like / share / save / view counts, sentiment derived from public comments |
| Derived Data | Audit findings, brand-guideline compliance scores, and analytical outputs generated by the Services in relation to a piece of content or an account |
| Technical data | IP address, device and browser identifiers, operating system, timestamps, cookie and session identifiers, referrer, and logs of Processing of Customer Personal Data |
| Consent records | Records of notices shown and consents given or withdrawn through Live2.ai components (Section 6.8) |
None requested, required or intentionally Processed. Customer is contractually prohibited from submitting the categories listed in Section 4.3. Woovly does not derive, infer, classify, index or make searchable any special category of data, and operates no feature that identifies individuals by any characteristic listed in Article 9 of the EU GDPR. The treatment of incidental content is governed by Section 4.4.
The DPDP Act does not establish a category of sensitive personal data. Until Section 44(2) of the DPDP Act comes into force, Woovly treats any biometric information as sensitive personal data or information under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Continuous, for the duration of the Agreement.
The Services do not perform data enrichment, identity resolution, profile appending, or the transfer of Customer Personal Data to data brokers or data feed providers.
To provide the Services to Customer as described in the Agreement and the applicable Order Form(s), and for no other purpose. See Sections 5.1 to 5.4, including the prohibition on use for model training.
| Data category | Retention |
|---|---|
| Customer Personal Data in production systems | For the term of the Agreement, then deleted in accordance with Section 9.2 |
| Ingested content and audit findings | For the term, or such shorter period as Customer configures in the Services. Configurable options are 12, 24 or 36 months from ingestion; the default is 24 months. Content no longer publicly available at source is erased under Section 3.5 |
| Logs of Processing of Customer Personal Data | Twelve (12) months minimum, as required by Rule 6(1)(e) of the DPDP Rules; maximum eighteen (18) months, then deleted |
| Personal Data, associated traffic data and logs of processing, where Section 9.8 applies | One (1) year from the date of processing, as required by Rule 8(3) of the DPDP Rules, in restricted storage, then erased (Section 9.8) |
| Consent records (Section 6.8) | For the term of the Agreement and for as long afterwards as Customer may need them to meet Section 6(10) of the DPDP Act, then returned to Customer or deleted |
| Backups | Rolling cycle; purged within ninety (90) days |
| Data retained on Customer's erasure instruction | Deleted within thirty (30) days (Sections 6.5, 9.6), subject to Section 9.8 |
The subject matter, nature and duration of Processing by each Sub-processor are as described in Annex 3. Each Sub-processor Processes Customer Personal Data only to the extent necessary to provide the function stated against its name, and is bound by written terms meeting Section 5.7(b).
This Annex completes Annex II of the EU SCCs and is the description of the technical and organisational measures implemented by Woovly as data importer / Data Processor under Article 32 of the EU GDPR and Rule 6 of the DPDP Rules.
1.1 Organisation. Woovly designates qualified security personnel responsible for the development, implementation and ongoing maintenance of its Information Security Programme.
1.2 Policies. Management reviews and approves all security policies, which address the confidentiality, integrity, availability and resilience of Customer Personal Data. Policies are reviewed and updated at least annually.
1.3 Standards. Woovly operates an information security management system aligned to the requirements of ISO/IEC 27001:2022. Where Woovly holds a current certification or attestation report, including ISO/IEC 27001:2022 certification or a SOC 2 Type II report, it makes the certificate or report available to Customer under Section 5.13(a). Woovly shall notify Customer if any certification on which Customer relies lapses or is withdrawn.
1.4 Risk assessment. Woovly engages an independent third party to perform a risk assessment of systems containing Customer Personal Data at least annually.
1.5 Risk treatment. Woovly maintains a formal risk treatment programme comprising penetration testing, vulnerability management and patch management.
1.6 Vendor management. Woovly maintains a vendor management programme covering security due diligence, contractual data protection terms, and periodic review of Sub-processors.
1.7 Privacy by design. Data protection requirements are assessed at the design stage of new features and material changes, and data minimisation and purpose limitation are applied by default.
2.1 Personnel are required to conduct themselves in accordance with Woovly's policies on confidentiality, business ethics, acceptable use and professional standards.
2.2 Woovly conducts background checks appropriate to the role on personnel who will have access to Customer Personal Data, covering employment history and criminal records, to the extent permitted by applicable labour law.
2.3 Personnel execute a written confidentiality agreement on hire and must acknowledge receipt of and compliance with Woovly's confidentiality, privacy and security policies.
2.4 Personnel receive privacy and security training on induction and at least annually. Personnel handling Customer Personal Data complete additional role-appropriate training.
2.5 Access rights are revoked promptly on termination or change of role.
3.1 Access management. A formal process governs the request, approval, provisioning, review and revocation of all access to Customer Personal Data. Access is granted on the principles of least privilege and need to know, based on documented job responsibilities.
3.2 Access review. Access rights are reviewed at least quarterly, and unnecessary access is revoked.
3.3 Authentication. Administrator and end-user access to the Services requires authentication via multi-factor authentication or single sign-on. Unique user IDs are mandatory; shared accounts are prohibited. Password policies enforce complexity, rotation, lockout, restrictions on reuse, and re-authentication after inactivity.
3.4 Privileged access. Administrative and production access is restricted to a minimal set of named personnel, is separately approved, and is logged.
3.5 Audit trail. Approvals are managed through workflow tools that retain records of all access changes. All access to systems holding Customer Personal Data is logged.
4.1 In transit. All Customer Personal Data transmitted over public networks is encrypted using TLS 1.2 or higher. Plain-text transmission of Customer Personal Data is disabled.
4.2 At rest. All Customer Personal Data at rest in production databases, object storage and backups is encrypted using AES-256 or an equivalent or stronger algorithm, using the encryption-at-rest capabilities of Google Cloud Platform and MongoDB Atlas.
4.3 Key management. Encryption keys are managed through the cloud provider's managed key service, with access restricted to authorised personnel and key rotation applied in accordance with provider defaults or better.
4.4 Additional measures. Where appropriate to the risk, Woovly applies pseudonymisation, masking, obfuscation or tokenisation to Customer Personal Data, as contemplated by Rule 6(1)(a) of the DPDP Rules.
5.1 Systems Processing Customer Personal Data have logging enabled to a central log facility, capturing access to and actions on Customer Personal Data sufficient to detect unauthorised access and to support investigation.
5.2 Logs are retained for a minimum of twelve (12) months, in accordance with Rule 6(1)(e) of the DPDP Rules (and, where Section 9.8 applies, Rule 8(3)), and are protected against alteration and unauthorised access.
5.3 Logs are monitored for anomalous activity and attempted or actual intrusion.
6.1 Data centres. Production infrastructure is hosted on Google Cloud Platform, in the asia-south1 (Mumbai, India) region, with failover capability to asia-south2 (Delhi NCR, India). Woovly does not operate its own physical data centres; physical and environmental security is provided by the cloud provider under its own certifications.
6.2 Resilience. Production workloads are deployed across multiple availability zones. Databases and file systems are replicated between availability zones.
6.3 Backups. Backups are taken on a regular schedule, are encrypted, and restoration testing is performed at defined intervals to verify recoverability.
6.4 Disaster recovery. Woovly maintains, plans and regularly tests a disaster recovery programme. Recovery objectives are a Recovery Time Objective (RTO) of eight (8) hours and a Recovery Point Objective (RPO) of four (4) hours. Disaster recovery tests are performed at least annually and the results are available to Customer under Section 5.13(a).
6.5 Hardening. Servers are hardened for the application environment. A code review process applies to changes affecting the security of the Services.
6.6 Network perimeter. Google Cloud firewall controls protect the production environment. Production, development and test environments are segregated.
6.7 Vulnerability management. Regular vulnerability scans are performed across production and development infrastructure. Vulnerabilities are remediated on a risk basis; critical, high and medium severity patches are applied as soon as commercially practicable.
6.8 Penetration testing. Independent penetration testing is performed at least annually. Executive summaries are available to Customer under Section 5.13(a).
7.1 Multi-tenancy. Customer Personal Data is stored in a multi-tenant environment. Woovly logically isolates the data of each customer, and enforces tenant separation at the application and data access layers.
7.2 Authentication system. A central authentication system is used across the Services to ensure uniform enforcement of access controls.
7.3 Secure disposal. Woovly applies documented data destruction processes to render Customer Personal Data irrecoverable on deletion, in accordance with Section 9.
8.1 Woovly maintains documented incident management policies and procedures, including severity classification and escalation paths.
8.2 Woovly monitors multiple channels for indications of security incidents, and its security personnel respond promptly to suspected or known incidents, contain and mitigate their effects, preserve evidence, and document the incident and its outcome.
8.3 Security incidents are reviewed to determine root cause and corrective action.
8.4 Notification to Customer is governed by Section 5.10 of this Addendum, including the 24-hour notification deadline.
Woovly imposes on each Sub-processor, by written contract, the protections required by Section 5.7(b), and verifies them through the vendor management programme described in paragraph 1.6 of this Annex 2.
10.1 Third-party content. Woovly applies measures designed to reduce the risk that text in third-party content (such as OCR output, transcripts and public comments) influences model outputs. These measures include delimiting content-derived text so that it is passed to models as data, applying injection-detection classification, and running scoring components without tool or network access. These measures reduce, but do not eliminate, that risk. Outputs are subject to human review under Section 5.4.
10.2 Data minimisation. Raw images, video frames, audio and any facial or biometric imagery are Processed only by self-hosted models within Woovly's infrastructure in India. Only derived textual signals are passed to the AI Providers listed in Part B of Annex 3.
Current as at 17 September 2026. Changes are notified in accordance with Section 5.7.
| # | Sub-processor | Function | Categories of data | Location of processing |
|---|---|---|---|---|
| 1 | Google Cloud Platform (Google Cloud India Pvt Ltd / Google LLC) | Hosting of production environment (GKE), application and databases; object storage; backups | All categories | India — asia-south1 (Mumbai), failover asia-south2 (Delhi NCR) |
| 2 | Google Workspace | Business email and document collaboration; support correspondence | Tenant user data; Customer Personal Data included in support correspondence | India |
| 3 | MongoDB Atlas (MongoDB Inc.) | Managed document database for application data | All categories | India — asia-south1 (Mumbai) |
| 4 | New Relic, Inc. | Application performance monitoring and error alerting | Technical data; incidental account identifiers in stack traces | USA |
| 5 | Hotjar Ltd | Product analytics on Woovly-operated marketing and administrative web properties only. Not deployed within the customer-facing Services or embedded components | Technical data | Malta / EU (Hotjar hosts within the EU) |
| 6 | Atlassian Corporation | Work and issue management; customer support ticketing | Tenant user data; content submitted in support tickets | USA |
| 7 | GitHub, Inc. | Source code version control | No Customer Personal Data in the ordinary course | USA |
| 8 | Slack Technologies (Salesforce, Inc.) | Internal messaging; incident coordination | Tenant user data; incident-related data | USA |
| 9 | Cloudflare, Inc. | Web application firewall, DDoS protection, CDN and edge TLS termination | Technical data (IP address, request metadata); content in transit only, not stored at rest | Global anycast edge, with India-preferred routing |
Woovly's invoicing (Zoho Corporation Pvt Ltd) and payment gateway (Razorpay Software Pvt Ltd) Process billing data that Woovly controls under Section 2.3, and are described in the Woovly Privacy Policy.
| # | AI Provider | Function | Categories of data | Location of processing | Data retention | Contractual no-training commitment |
|---|---|---|---|---|---|---|
| A1 | OpenAI, L.L.C. | Reasoning and lightweight large language model inference: compliance scoring against Customer's brand rules, rule-matching judgment, slot-level feedback, tone and injection-detection classification | Derived textual signals only — transcript text, OCR-extracted on-screen text, structured output of the self-hosted vision model, and the compiled rule prefix. Raw images, video frames, audio and biometric or facial imagery are not transmitted | USA / EU endpoints per Customer configuration | OpenAI may retain data where required by law or court order | Yes — OpenAI Data Processing Addendum with no-training commitment; OpenAI does not train on API data by default |
| A2 | Google Cloud Vertex AI (Google Cloud India Pvt Ltd / Google LLC) | Text embedding generation for brand-rule and content matching | Derived textual signals and brand-rule text | India — same GCP region as production (asia-south1) | Customer data is not stored by the service; in-memory data caching is disabled for Woovly's project | Yes — Google Cloud Data Processing Addendum; Vertex AI does not use customer data to train foundation models |
Self-hosted models — not Sub-processors. The following models run inside Woovly's own GKE cluster in India and involve no transfer of Customer Personal Data to any third party: the multi-modal vision model (frame and image understanding, logo and product detection, brand-safety flags), the demographic inference model (Gemma), speech-to-text (Whisper) and optical character recognition (PaddleOCR). Raw images, video frames, audio and any facial or biometric imagery are Processed exclusively in-cluster and never egress to an AI Provider. Only derived textual signals are passed to the AI Providers listed above. Measures applied to third-party content are described in paragraph 10 of Annex 2.
Woovly contracts with each AI Provider under that provider's enterprise data processing terms. Woovly does not route Customer Personal Data or Customer Content through any consumer-tier or shared-data AI service, and does not use any intermediary AI gateway or aggregator that would place Customer Content outside the contractual chain described in Section 5.7(b).
These terms apply to the extent Woovly Processes Personal Data subject to the CCPA or another US State Privacy Law.
1. Role. Customer is a Business; Woovly is a Service Provider. Woovly Processes Personal Data solely on behalf of Customer and pursuant to the written instructions in Section 4.2.
2. Certification. Woovly certifies that it understands the restrictions in this Annex 4 and in Section 5.1, and will comply with them.
3. Restrictions. Woovly shall not: (a) Sell or Share Personal Data; (b) retain, use or disclose Personal Data for any purpose other than the Business Purposes specified in paragraph 5, or as otherwise permitted by the CCPA; (c) retain, use or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data received from or on behalf of Customer with Personal Data received from or on behalf of any other person, or collected from Woovly's own interaction with consumers, except as permitted by Section 5.8 and the CCPA.
4. Level of protection. Woovly shall comply with the obligations that apply to it under the CCPA and shall provide the same level of privacy protection as the CCPA requires of Businesses.
5. Business Purposes. The following Business Purposes are selected for Processing involving California consumers:
| Business Purpose | |
|---|---|
| ☐ | Auditing related to counting ad impressions to unique visitors, verifying positioning and quality of ad impressions, and auditing compliance with applicable standards |
| ☑ | Helping to ensure security and integrity, to the extent the use of the consumer's personal information is reasonably necessary and proportionate for these purposes |
| ☑ | Debugging to identify and repair errors that impair existing intended functionality |
| ☐ | Short-term, transient use, including non-personalised advertising shown as part of a consumer's current interaction with the business |
| ☑ | Performing services on behalf of the business, including maintaining or servicing accounts, providing customer service, verifying customer information, processing payments, providing analytic services, or providing storage |
| ☐ | Providing advertising and marketing services, except for cross-context behavioural advertising |
| ☐ | Undertaking internal research for technological development and demonstration |
| ☑ | Undertaking activities to verify or maintain the quality or safety of the Services provided to Customer, subject to Sections 5.2 and 5.3 |
| ☑ | Retaining and engaging another service provider or contractor as a subcontractor, where the subcontractor meets the requirements for a service provider or contractor under the CCPA |
| ☑ | Preventing, detecting or investigating data security incidents, or protecting against malicious, deceptive, fraudulent or illegal activity |
6. Notification. Woovly shall notify Customer if it determines it can no longer meet its obligations under the CCPA, and Customer may take reasonable steps to stop and remediate unauthorised use.
7. Sensitive Personal Information. Woovly does not Process Sensitive Personal Information for the purpose of inferring characteristics about a consumer.
8. Consumer rights. Woovly shall assist Customer in responding to consumer requests to know, delete, correct, opt out of sale or sharing, and limit the use of Sensitive Personal Information, in the manner set out in Section 6.
End of Data Protection Addendum.
LIVE2.AI APPS AVAILABLE ON

PRODUCTS
Shoppable Social Wall
Social Media Publishing & Reporting
RESOURCES
Blog
Help Center/ Support Documentation
Integrations
FAQs
© 2026, Woovly India Pvt Ltd. All Rights Reserved.