Woovly India Pvt Ltd (operating as Live2.ai)
Language. This Policy is available in English. Each consent request we make lets you read it in English or in any of the languages listed in the Eighth Schedule to the Constitution of India. You may also ask for this Policy in any of those languages by writing to privacy@live2.ai, and we will provide it within 14 days (Sections 5(3) and 6(3) of the Digital Personal Data Protection Act, 2023).
Companion document. Where we process personal data on behalf of a business customer, our Data Protection Addendum governs that processing and forms part of our Terms of Use. This Privacy Policy and the DPA are maintained together.
Woovly India Pvt Ltd, a company incorporated in India, operating under the brand Live2.ai, is the data controller (under the EU and UK GDPR), the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023) and the Business (under the CCPA) in respect of the personal data described in this Policy.
| Registered office | Flat No. 001, Ground Floor, HM Delphi, 7th C Main, 3rd Block, Koramangala, Bengaluru, Karnataka, 560068, India |
| General privacy enquiries | privacy@live2.ai |
| Data Protection Officer | Yash Arora — dpo@live2.ai |
| Grievance Officer (India) | Yash Arora — grievance@live2.ai |
| Security / incident reporting | security@live2.ai |
Our Data Protection Officer and Grievance Officer are based in India. We have appointed a Data Protection Officer voluntarily. They are the person able to answer your questions about how we process your personal data, under Section 8(9) of the DPDP Act and Rule 9 of the DPDP Rules, and their contact details are included in every response we send to a rights request. We aim to acknowledge every enquiry within three (3) business days and to give a substantive response within thirty (30) days.
This Policy explains how we handle personal data when:
Where we act only as a processor. For use cases 3, 4 and 5, and for content that customers upload to the Platform, we usually act as a processor / Data Processor on behalf of our business customer, who decides what content is analysed and why. In those cases the customer is the controller and its own privacy notice governs; our role is set out in our DPA. We have still described that processing below so you can see what happens to your data.
| Data | IP address, device and browser type, operating system, pages viewed, referring URL, timestamps, cookie and session identifiers |
| Why | To operate and secure the Website, analyse traffic, and improve our content |
| Basis — EU/UK | Legitimate interests (running and securing our site); consent for non-essential cookies |
| Basis — India | Consent, requested through our cookie banner before any non-essential cookie is set. The technical data needed to deliver and secure a page you request is processed under Section 7(a) of the DPDP Act, for that purpose only |
| Data | Full name, business email, phone number, job title, company name, country, hashed credentials, role and permissions, login history, and billing contact details |
| Why | To create and administer your account; provide the Platform; provide support; send service communications; process payments; prevent misuse |
| Basis — EU/UK | Performance of a contract; legitimate interests (security, fraud prevention); consent for marketing |
| Basis — India | Consent, which we request when you sign up. If a customer's administrator invites you, we process your details as that customer's Data Processor until you first log in and accept our notice. Billing and tax records are kept because Indian law requires it (Section 8(7)). Marketing always relies on consent |
| Do you have to give it? | You need to give us your account details to use the Platform. Without them we cannot open an account for you |
Content that you or your organisation upload to the Platform (video, images, captions, brand guidelines) is processed on the customer's behalf under our DPA, not under this Policy.
Payment card details are collected and processed directly by our payment gateway (Razorpay). We do not see or store them.
| Data | IP address, device identifiers, interaction events (views, clicks, dwell time), and any comment, name, email or phone number you choose to submit |
| Why | To display the content, record interactions, and report engagement to our customer |
| Role | We act as processor for our customer |
| Data | Email address and preferences (for example, saved videos) |
| Why | To register you, send registration emails, and save your preferences |
| Role | We act as processor / Data Processor for the customer |
| Sharing | This data is made available to the customer whose website you registered from. That customer is the controller / Data Fiduciary for it, and its own privacy notice applies |
| Data | Name, email address, phone number, company name, job title, country, and the content of your messages |
| Why | To answer questions, provide support, manage supplier and customer relationships, and — where you have agreed — send marketing |
| Basis — EU/UK | Legitimate interests; consent for marketing |
| Basis — India | Consent; or Section 7(a) of the DPDP Act where you voluntarily give us your details for a specified purpose (for example, a support request) and have not told us you do not consent. Where your employer gave us your business contact details, we use them only to manage that business relationship, and we tell you so when we first contact you. Marketing always relies on consent |
This is the category most people do not expect, so we set it out plainly.
Our Platform analyses content that has already been published on social media. Where a customer connects its own accounts, or configures the Platform to monitor specified public accounts — for example, creators it has engaged, or accounts it benchmarks against — we ingest and analyse that published content.
| Data | Social handle, display name, profile picture, biography, platform user ID, public follower counts, published posts and captions, images, video, audio, hashtags, publicly visible comments and their authors, engagement counts, and any personal data appearing within that content. We also generate findings and scores about that content for the customer |
| Why | To assess published content against the customer's brand guidelines and campaign criteria, and to produce audit findings and reports for that customer |
| Role | We act as a processor for the customer. The customer decides which accounts are monitored and is responsible for the lawfulness of that decision, and for giving you notice where required |
| Basis — EU/UK | Determined by the customer as controller, typically legitimate interests |
| Basis — India | Where content has been made publicly available by the individual themselves, Section 3(c)(ii)(A) of the DPDP Act provides that the Act does not apply to it. That exemption does not cover: other people's data within the content (for example, a third person appearing in a creator's video); findings and scores generated about you, which you have not made public; or content that is no longer public. For that data, the customer, as Data Fiduciary, must have your consent or another lawful ground, and we process it only as its Data Processor under a contract meeting Section 8(2) of the DPDP Act. Where a customer has no such ground for an individual's account, our DPA limits it to aggregate benchmarking that does not identify you. We apply the security, retention and deletion safeguards in this Policy to all of this data, exempt or not |
If we become aware that content we ingested has been deleted or made private at source, we erase our copy within 30 days, unless the customer has another lawful basis for keeping it. To find out which customer is analysing your content, or to exercise your rights, contact us as described in Section 9.
What we do not do. We do not build profiles of individuals for sale, sell or share this data, enrich it with data from brokers, or use it to train AI models. See Sections 4 and 6.
We may also use any of the above personal data to detect and prevent fraud and illegal activity, fix errors, conduct audits, maintain security, comply with law, respond to lawful requests from authorities, and establish or defend legal claims. For individuals in India, these uses rely on consent where you have given it, or on Sections 7(d) and 7(e) and Sections 17(1)(a) and 17(1)(c) of the DPDP Act.
We also produce aggregated, de-identified statistics about how the Platform operates. These statistics cannot identify you or any customer, and we do not attempt to re-identify them.
The DPDP Act does not recognise "legitimate interests" or "performance of a contract" as lawful bases. For individuals in India we rely on consent, or on one of the narrow "certain legitimate uses" in Section 7 of the DPDP Act, most often Section 7(a): data you have voluntarily given us for a specified purpose, where you have not told us you do not consent. Where this Policy cites legitimate interests or contract, that basis applies only under the EU and UK GDPR.
When we ask for your consent, we do so in a separate notice, in clear and plain language, at the point of collection. That notice lists the data we will collect and why, and links to how you can withdraw consent, exercise your rights and complain to the Data Protection Board of India (Section 5 of the DPDP Act and Rule 3 of the DPDP Rules). Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose (Section 6(1)). We do not make a service conditional on consent to processing that the service does not need. We keep a record of each notice we give and each consent given or withdrawn, as Section 6(10) requires. Where a Consent Manager registered with the Board is available to you, you may give, manage, review and withdraw your consent through it (Section 6(7)).
If you gave us consent before the DPDP Act's notice requirements came into force, we will send you a separate notice by email or in-app message, as Section 5(2) of the DPDP Act requires. You may withdraw that consent at any time, as described in Section 9.3.
We do not seek, and ask you not to send us, special category data — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data about sex life or sexual orientation — nor government identification numbers or payment card numbers.
Published social media content can incidentally contain such information; for example, a person's appearance may be visible in an image. We do not derive, infer, classify, index or make searchable any such characteristic, and we operate no feature that identifies people by them.
Our Platform uses artificial intelligence to analyse published content. We think you should know exactly how that works.
What runs on our own systems. Image and video understanding, demographic inference, speech-to-text transcription and optical character recognition all run inside our own infrastructure in India. Raw images, video frames, audio and any facial imagery are processed there and are never sent to a third-party AI provider.
What leaves our systems. Only derived text — transcripts, text extracted from images, the structured output of our own vision model, and the customer's compiled brand rules — is sent to external language models for scoring and reasoning. These are:
| Provider | Purpose | Safeguards |
|---|---|---|
| OpenAI | Compliance scoring, rule matching, feedback generation | No-training commitment under the OpenAI DPA |
| Google Cloud Vertex AI | Text embeddings for content and rule matching | Processed in our India region; no use of customer data to train foundation models |
We do not use your personal data or your content to train AI models — not our own, and not anyone else's. This is a contractual commitment, flowed down to every AI provider we use. We do not route data through consumer-tier AI services or third-party AI gateways.
Automated decisions. Our outputs are analytical and advisory, and are designed to be reviewed by a customer's team before anyone acts on them. We do not ourselves make decisions about individuals by automated means that produce legal or similarly significant effects (Article 22 GDPR), and our DPA requires customers to apply meaningful human review before relying on our outputs for such decisions. If you believe a decision about you was based solely on our output, contact the customer concerned or us, and we will help you obtain human review.
We use cookies and similar technologies on our Website and Platform.
| Type | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing | No |
| Functional | Remembering preferences and settings | Yes, in the EU/UK and India |
| Analytics | Understanding how the Website and Platform are used | Yes, in the EU/UK and India |
Where consent is required we ask for it before setting non-essential cookies, and you can change or withdraw your choice at any time through the cookie settings link in the Website footer. Withdrawing consent is as straightforward as giving it.
You can also block cookies in your browser, and opt out of Google Analytics specifically using Google's opt-out browser add-on.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We share personal data with the service providers below, each under a written data processing agreement that obliges them to protect it and to use it only for the purpose stated.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, databases, storage, backups | India — asia-south1 (Mumbai), failover asia-south2 (Delhi NCR) |
| MongoDB Atlas | Application database | India — asia-south1 (Mumbai) |
| Cloudflare | Web application firewall, DDoS protection, CDN | Global edge, India-preferred routing |
| Google Workspace | Business email and documents | India |
| Razorpay | Payment gateway (independent controller for card data) | India |
| Zoho | Invoicing | India |
| Provider | Purpose | Location |
|---|---|---|
| New Relic | Application performance monitoring, error alerting | USA |
| Sentry | Error monitoring and alerting | USA |
| Atlassian | Work management and support ticketing | USA |
| Slack | Internal messaging, incident coordination | USA |
| GitHub | Source code version control (no customer personal data in the ordinary course) | USA |
| Provider | Purpose | Location |
|---|---|---|
| Google Analytics | Website usage analytics | USA / EU |
| Hotjar | Product analytics on our marketing and administrative pages only — not deployed in the customer-facing Platform | Malta / EU |
| Redash | Internal analytics | USA |
| Provider | Purpose | Location |
|---|---|---|
| OpenAI | Compliance scoring and reasoning on derived text only, as described in Section 4 | USA / EU |
| Google Cloud Vertex AI | Text embeddings, as described in Section 4 | India — asia-south1 (Mumbai) |
We may also disclose personal data:
Where our customer configures an integration with a third-party service, content is shared with that service at the customer's instruction and under the customer's control, not ours.
We store personal data primarily on Google Cloud Platform in India (asia-south1, Mumbai), with failover to asia-south2 (Delhi NCR). Our teams access it from our offices in India.
Some of the providers listed in Section 6 process personal data outside India, including in the United States and the EU.
Transfers out of the EU, UK and Switzerland. Where we transfer personal data from these regions to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, as modified by the UK International Data Transfer Addendum for UK transfers and adapted for Switzerland. Details are in Section 8 of our DPA. You can request a copy of the relevant safeguards from privacy@live2.ai.
Transfers out of India. We comply with Section 16 of the DPDP Act and Rule 15 of the DPDP Rules. India permits transfers except to countries the Central Government restricts by notification; we monitor those notifications and will relocate processing if a provider's location becomes restricted.
| Data | Retention |
|---|---|
| Account data | For the life of your account, then deleted within 30 days of closure (subject to the one-year processing records row below) |
| Content ingested for audit, and audit findings | Configurable by the customer — 12, 24 or 36 months from ingestion; default 24 months. Content deleted or made private at source is erased within 30 days of our becoming aware of it |
| Security, access and audit logs | 12 months minimum (required by Rule 6(1)(e) of the DPDP Rules), 18 months maximum |
| Records of processing — the personal data, associated traffic data and logs of a processing activity | From the date Rule 8(3) of the DPDP Rules comes into force: one year from the date of that processing, as that Rule requires, even if you close your account or ask us to delete your data. During that year the records are held in restricted storage and used only for the purposes in the Seventh Schedule to the DPDP Rules (lawful requests from the State) and, under Rule 6(1)(e), to detect and investigate unauthorised access. They are then erased |
| Records of notices and consents | For as long as we rely on the consent, and afterwards for as long as we may need to show that it was validly given (Section 6(10)) |
| Backups | Rolling cycle, purged within 90 days |
| Support correspondence | 24 months from closure of the request. Customer data included in a support ticket is deleted in line with our DPA |
| Marketing contact data | Until you opt out, then suppressed |
| Billing, financial and tax records | 8 years (section 128, Companies Act 2013, and applicable tax law) |
| Data subject to a deletion request | Deleted within 30 days (subject to the one-year processing records row above) |
We delete or anonymise personal data once the purpose for which we collected it has been served and no legal obligation requires us to keep it, as required by Section 8(7) of the DPDP Act.
| Right | EU / UK | India | California |
|---|---|---|---|
| Know what data we hold and how we use it | ✓ | ✓ (a summary, s.11(1)(a)) | ✓ |
| Know who we have shared your data with, and what we shared | ✓ | ✓ (s.11(1)(b)) | ✓ |
| Get a copy of your data | ✓ | ✓ (offered voluntarily; the Act requires a summary) | ✓ |
| Correct inaccurate data | ✓ | ✓ | ✓ |
| Delete your data | ✓ | ✓ | ✓ |
| Restrict how we use it | ✓ | — | — |
| Object to our use of it | ✓ | — | — |
| Data portability | ✓ | — | ✓ |
| Withdraw consent at any time | ✓ | ✓ | — |
| Nominate someone to exercise your rights if you die or become incapacitated | — | ✓ (s.14 DPDP) | — |
| Opt out of sale or sharing | — | — | ✓ (we do neither) |
| Have a grievance resolved by us | ✓ | ✓ (s.13) | ✓ |
| Complain to a regulator | ✓ | ✓ | ✓ |
| Not be discriminated against for exercising a right | — | — | ✓ |
Your right to object to direct marketing. You may object at any time to our use of your personal data for direct marketing, and we will stop (Article 21(3) GDPR).
Email privacy@live2.ai, or the Grievance Officer at grievance@live2.ai. So that we can find your data, please tell us the identifier we hold for you. These are the identifiers we require, published under Rule 14(1)(b) of the DPDP Rules:
We may ask for further information to verify your identity, but only what we need for that purpose. We will acknowledge within three (3) business days and respond substantively within thirty (30) days. Thirty days is also the period within which we respond to grievances, as published under Rule 14(3) of the DPDP Rules and Section 13(2) of the DPDP Act. Deletion requests are actioned within thirty (30) days.
Where we process your data on behalf of a customer (Section 2), we will pass your request to that customer within five (5) business days and help it respond, and we will tell you that we have done so and which customer it is.
For individuals in India, we do not charge a fee or decline a request as excessive. For others, there is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline — and we will explain why.
Where we rely on your consent, you can withdraw it at any time, and doing so is as easy as giving it — by emailing privacy@live2.ai, through the cookie settings link, or via the unsubscribe link in any marketing email. Withdrawal does not affect processing carried out before you withdrew.
Under Section 14 of the DPDP Act and Rule 14(4) of the DPDP Rules, you may nominate one or more individuals to exercise your rights if you die or become incapable of doing so. To nominate, email privacy@live2.ai from the address registered with us and give each nominee's full name, relationship to you, email address and phone number. You can change or cancel a nomination the same way. A nominee who wishes to act must write to us with proof of the death or incapacity and proof of their own identity.
Email privacy@live2.ai. We will delete your account data within 30 days, subject to the retention exceptions in Section 8, including the one-year processing records required by Rule 8(3) of the DPDP Rules once that Rule is in force.
Note that if you have posted content publicly through a customer's site, that content may have been copied or cached by others beyond our control. We will delete our copies; we cannot delete theirs.
Use the unsubscribe link in any marketing email, or email privacy@live2.ai. We action opt-outs promptly.
Please come to us first, at privacy@live2.ai or grievance@live2.ai — we would rather fix it. You also have the right to complain to a regulator:
When you exercise your rights under the DPDP Act, Section 15 requires you to: comply with applicable law; not impersonate another person; not suppress material information when providing personal data for any document, unique identifier or proof of identity or address issued by the State; not register a false or frivolous grievance or complaint; and give only information that can be verified as authentic when you ask us to correct your data.
Our Website, Platform and services are not intended for children (anyone under eighteen (18)).
Before any non-essential cookie is set, our cookie banner asks you to confirm that you are 18 or over. If you do not confirm, we set only strictly necessary cookies.
In line with Section 9(3) of the DPDP Act, we do not track or behaviourally monitor children, do not serve advertising directed at children, and operate no feature that estimates or infers a person's age. Our DPA prohibits customers from using the Platform to monitor accounts they know, or have reason to believe, are operated by children.
If you are under 18, please do not send us your personal data. We do not process the personal data of children, or of persons with a disability who have a lawful guardian, without verifiable consent from their parent or lawful guardian obtained as required by Section 9 of the DPDP Act and Rules 10 and 11 of the DPDP Rules. We do not currently seek such consent. If we learn that we hold a child's personal data without verifiable consent, we will delete it within thirty (30) days. If you believe we hold such data, contact privacy@live2.ai.
We maintain an information security management system aligned to the requirements of ISO/IEC 27001:2022. Our measures include:
No system can be guaranteed secure. Please protect your own credentials and devices, and tell us at security@live2.ai if you suspect a problem.
If a personal data breach affects you, we will notify you and the relevant regulators as required:
Where we process your data on behalf of a customer, we notify that customer within 24 hours so that it, as Data Fiduciary, can notify you and the Board. The terms are in Section 5.10 of our DPA.
Our Website and Platform can link to or interact with services we do not control. We are not responsible for their privacy practices or content. Please read their own policies.
We review this Policy at least annually and update it as our services or the law change. The version number and date at the top always tell you which version applies. If we make a significant change to how we use personal data, we will post a notice on the Website and Platform and, where required, contact you directly. Where a change adds a new purpose for data we process on the basis of your consent, we will give you a fresh notice and ask for your consent before we process your data for that purpose. Previous versions are available on request.
| General privacy | privacy@live2.ai |
| Data Protection Officer | Yash Arora — dpo@live2.ai |
| Grievance Officer (India) | Yash Arora — grievance@live2.ai |
| Security | security@live2.ai |
| Post | Woovly India Pvt Ltd, Flat No. 001, Ground Floor, HM Delphi, 7th C Main, 3rd Block, Koramangala, Bengaluru, Karnataka, 560068, India |
Nothing in this Policy limits your statutory rights or your access to any remedy.
LIVE2.AI APPS AVAILABLE ON

PRODUCTS
Shoppable Social Wall
Social Media Publishing & Reporting
RESOURCES
Blog
Help Center/ Support Documentation
Integrations
FAQs
© 2026, Woovly India Pvt Ltd. All Rights Reserved.