Last Update: July 10, 2025
Live Elements Ecosystem S.L. ("we", "us", "our") is the data controller for the personal data described in this Privacy Policy, except where stated otherwise.
This Privacy Policy for Live Elements Ecosystem S.L. ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use:
Related Documents:
We collect information you submit directly to us, for example when you create an account, manage an organization, configure projects, request support, or communicate with us.
Please avoid sending sensitive personal data (e.g., health, biometric, precise geolocation, government IDs) in tickets or free-text fields unless we specifically request it and you have a lawful basis.
When you use the CMS, Console, or Sites, we automatically collect certain information to provide, secure, and improve the services. See Cookies, Tracking & Analytics for details on cookies/SDKs.
We may collect these via our own logs/SDKs as well as service providers operating on our behalf.
Unless expressly permitted in writing by us in an applicable Order Form or Documentation, you shall not submit to, process, or store in the Services any Prohibited Data, including:
You acknowledge and agree that:
We and our service providers use cookies and similar technologies (collectively, "Cookies") to run and secure the CMS (SaaS), the Console, and our Sites, and to understand how they’re used. These include cookies,local/session storage, SDKs, and tags.
When we act as your processor for Service Data in the CMS, Cookie-based processing is limited to operating and securing the service under your instructions and our DPA.
Cookie Notice: https://ecosystem.liveelements.io/documents/cookie-policy (lists specific Cookies, providers, and durations).
Current status. We do not currently use advertising or remarketing Cookies on our Sites or Console. If enabled in the future: we may use Cookies to measure campaign performance and reduce repetitive ads. We will
We will not permit third-party advertising tags on Console or CMS admin pages that display or handle sensitive account data.
You can purchase and manage subscriptions to the CMS through the Console. We use third-party payment service providers to process payments securely. We do not collect or store full payment card numbers or security codes; those are handled directly by our payment provider(s).
We keep billing records for as long as your account is active and as necessary to meet legal, tax, and accounting requirements. After that, we retain only what’s needed to resolve disputes or comply with law, then securely delete or anonymize the data.
We use Stripe to process payments. We receive only the minimal information needed to reconcile payments and manage your subscription. See their privacy/security documentation linked in our Cookie Notice or Sub-processor List.
When we process Service Data in the CMS, we act as your processor/service provider and handle it only on your instructions and the DPA. For everything else (e.g., Sites/Console/account data), we act as controller.
We use personal data to:
Where the GDPR/UK GDPR applies, we process personal data on these legal bases:
We disclose limited data to service providers (e.g., hosting/CDN, support/email, payments/MoR, observability/analytics where enabled) and affiliates under appropriate safeguards; as required for legal/compliance and safety; and in business transfers (e.g., merger/acquisition), with continued protection and notice where required.
When we act as your processor (CMS Service Data), we may engage vetted sub-processors under our DPA (see the current list: https://ecosystem.liveelements.io/documents/subprocessors-list ). We disclose Service Data only on your documented instructions or where legally required (we’ll notify you unless prohibited).
If you connect identity providers, plugins, or other integrations, their handling of data is governed by their terms and privacy notices.
Our Sites may include third-party links or social widgets that collect limited data (e.g., IP, page viewed). Their policies apply.
Content posted in community spaces, like public forums/chats may be read by others and indexed by search engines. Don’t share sensitive data there.
Personal data may be processed in EU and the United States, and in other countries where our service providers/sub-processors operate (see our Sub-processor List).
When personal data is transferred from the EEA/UK/Switzerland to countries that do not provide an adequate level of protection, we use appropriate safeguards, including:
We implement technical and organizational measures—including encryption in transit and at rest, access controls, and least-privilege permissions—and conduct transfer impact assessments (TIAs) for relevant transfers.
If we receive a legally binding request for personal data from a public authority, we will:
We retain personal data only as long as necessary for the purposes in this Policy, to operate the CMS/Console, to comply with legal/tax/accounting duties, to resolve disputes, and to enforce agreements. Where feasible, we anonymize or aggregate data instead of keeping it in identifiable form.
For Service Data in the CMS (where we act as processor), you control retention via settings and instructions in the DPA.
We aim to delete or anonymize Account/Console personal data within 60 days of account closure (except where longer retention is required by law or necessary to establish, exercise, or defend legal claims). Backups expire on their normal cycle; when restored for DR, we re-apply deletions as soon as practicable.
Backups are encrypted and kept only for business continuity. When you delete data, it is removed from active systems; it may persist in backup archives until those archives expire and are overwritten on their normal cycle. We don’t restore backups except for disaster recovery or to address significant security/operational issues; if Service Data re-appears after a restore, we re-apply deletion as soon as practicable.
We may retain certain limited personal information for a longer period where reasonably necessary to:
We will minimize the data we retain for these purposes, restrict access to authorized personnel only, and securely delete or anonymize the data once it is no longer needed for the purpose for which it was retained
Our CMS, Console, and Sites are not directed to children. We do not knowingly collect personal data from anyone under 16 in the EEA/UK (or the higher age where your jurisdiction requires it) or under 13 in the U.S. If you believe a child has provided personal data, contact us and we will delete it.
Depending on your location, you may have the right to access, correct, delete, restrict or object to processing, and port your data; and to withdraw consent where processing is based on consent.
Account Self Service: You can update organization, user, and billing details anytime via the Console. You may also remove users and delete projects where available.
Some U.S. state laws grant residents specific rights, including to know/access, correct, delete, obtain a copy, opt out of certain processing (e.g., "sale," "sharing," or targeted advertising), and appeal denials.
We do not sell or share personal data for cross-context behavioral advertising and do not use advertising/remarketing cookies on our Sites or Console. If this changes, we will update this Policy, honor GPC signals, and provide opt-out controls in Cookie Settings. We do not intentionally collect sensitive personal data via Console/Sites.
Submit via security@liveelements.io or our web form; we verify identity using account information and may request additional details. You may authorize an agent; we may require proof of authorization. If we deny your request, you can appeal as described above; if still unsatisfied, you may contact your state attorney general.
California residents may request information regarding our disclosures of certain categories of personal information to third parties for their direct marketing purposes during the prior calendar year.
Such requests may be submitted once per calendar year by contacting us at:
We will provide the required information in accordance with California Civil Code § 1798.83.
We may update this Policy from time to time. We will post the new effective date and, for material changes, provide a prominent notice (e.g., in-product banner or email) 7 days before they take effect, or obtain consent where required by law. Older versions may be available in our version history/changelog.
Primary contact (all requests): security@liveelements.io
• Privacy requests & questions: use the subject "Privacy Request" (e.g., access, deletion, objection). • Security/vulnerability reports: use the subject "Security" (please avoid including secrets; we’ll reply with a secure channel if needed).
If you are in the EEA/UK, you may also lodge a complaint with your supervisory authority. We encourage you to contact us first so we can try to resolve your concern quickly.