Skip to content
LIVOI
DE

LIVOI privacy policy

Last updated:

Contents

1. Who is responsible for your data

This policy applies to the LIVOI application. The website privacy notice applies to this website.

P-CATION Consulting and Solutions GmbH
Kirchstraße 44, 59823 Arnsberg, Germany
Privacy contact: privacy@p-cation.de

We are responsible for our contract administration, customer enquiries and our own security measures. If you use LIVOI through an organisation, we process its business data on its behalf. Your organisation is responsible for that content, access rights and retention; its privacy notices also apply.

2. What data we use and why

We process account and contact details, sign-in information and permissions to provide your access. Depending on use, this includes messages, documents, emails, attachments and other supplied media, along with work results and search data generated from them. Technical information such as IP addresses, device details and error logs supports operation and security. For contract or support enquiries, we also process correspondence and necessary billing information.

Data comes from you, your organisation, its communication partners and authorised external services, or is generated during use.

Where we act as controller, the following legal bases apply:

Your organisation determines the legal basis for its business data. Access cannot be provided without the required account information; external connections are necessary for their corresponding additional features.

3. Registration and sign-in

We use Clerk, Inc. for user accounts and authentication. This involves processing account, contact and session data and technical security information. When you sign in with Google or Microsoft, we receive authorised identity details such as your name, email address, profile information and account identifier. Your provider password is not sent to LIVOI. Signing in alone does not provide access to emails or calendars.

Providers also receive technical information about sign-in. Their own processing is covered by the privacy notices of Clerk, Google and Microsoft.

4. Google and Microsoft connections

You set up additional connections using the permissions displayed by the provider. We store account associations, authorisations and encrypted access tokens for your selected features and background tasks.

Google / Gmail: LIVOI uses your email address and profile information to associate your account and can retrieve, create, edit and delete Gmail labels. These permissions do not allow access to email content or attachments, sending emails or applying labels to individual messages.

Microsoft Outlook / Microsoft 365: LIVOI can import and process authorised messages and attachments, including senders, recipients, subjects and timestamps, and edit messages and mailbox categories to mark processing status. Configured automations may store matching content in LIVOI and send it to OpenAI for document analysis. Authorised people in your organisation can view content and results. This connection does not include sending emails.

Google data is subject to the Google API Services User Data Policy, including Limited Use, and the Google Workspace requirements. We use it only for the features described, do not sell it, and do not use it for advertising or to develop, improve or train generalised AI models. Transfers are limited to the authentication and operational providers needed for these features. Human access occurs only with express consent to access the specific data or within Google’s permitted security and legal exceptions.

You can remove connections in LIVOI and also revoke authorisation through Google account connections or Microsoft app permissions. Removal deletes the connection and access tokens from the active system; processing already underway may still finish. Imported content remains until separately deleted.

5. AI processing

For answers, summaries, document analysis, data extraction, drafts and search, we send the necessary inputs, files and context to OpenAI Ireland Ltd. (OpenAI API). We also use Google Cloud EMEA Limited (paid Gemini API) for semantic search. Content and derived search data are stored in LIVOI. Gemini is independent of connecting a Google account.

We do not use customer data to train our own AI models or voluntarily release it for providers’ general model training. Providers may retain data for security and abuse monitoring and have authorised personnel review flagged content: under the general terms, normally up to 30 days at OpenAI and 55 days at Gemini. Legal exceptions and feature-specific storage may apply.

AI results may be inaccurate. Your organisation provides information about any automated decisions with legal or similarly significant effects within that organisation.

6. Recipients, locations and security

The central infrastructure is hosted by Hetzner Online GmbH in Germany. Other recipients depend on the features used:

Authorised staff, service providers and advisers bound by confidentiality receive data as needed; authorities receive it where an appropriate legal basis applies.

How we protect your data, including Google user data: We encrypt transmissions using TLS and store connected account access tokens encrypted. Access is checked against identity, organisation and permissions. Internal access is restricted to authorised tasks.

External providers may process data outside the European Economic Area, particularly in the United States. Where we are responsible, transfers rely on adequacy decisions or appropriate safeguards under Articles 45 and 46 GDPR, particularly EU Standard Contractual Clauses with necessary supplementary measures. The EU-US Data Privacy Framework applies only to appropriately certified recipients and covered processing. Contact us for information and copies of the applicable safeguards.

7. Cookies and browser storage

Cookies and local browser storage support sign-in, security, organisation selection and your preferences, including through Clerk. Strictly necessary access relies on section 25(2)(2) of Germany’s TDDDG; access requiring consent relies on section 25(1) TDDDG. The legal bases in section 2 also apply to personal data.

Organisation selection is stored for up to one year, and the sidebar preference for up to seven days. Authentication data follows session settings; local preferences remain until changed or deleted in your browser. Removal may require you to sign in again.

8. Retention and deletion

We retain account data for as long as access is needed. Content and work results are retained according to your organisation’s instructions and deleted without undue delay or returned at the end of the service, unless statutory retention obligations apply. Operational logs are retained only as long as needed to troubleshoot errors or investigate security incidents. Contract and support data is retained for handling the matter, legal obligations and necessary legal claims.

Backups are cleared according to the deletion process, potentially later than the active system. Section 5 applies to AI services; WhatsApp may retain content and media for up to 30 days unless a configuration without content storage is enabled.

Deleting an account does not automatically remove shared organisation data or originals at other services. To delete data, use the available features or contact your organisation or our privacy contact.

9. Your rights and contact

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction and data portability. You may withdraw consent at any time for the future; this does not affect the lawfulness of earlier processing.

You may object to processing based on legitimate interests on grounds relating to your particular situation. We will stop unless overriding compelling legitimate grounds apply or processing is needed to establish, exercise or defend legal claims. You may object to direct marketing at any time without giving reasons.

Contact: privacy@p-cation.de. For your organisation’s data, we assist it in handling your request. You may also complain to a data protection authority, particularly where you live or work. The authority responsible for our registered office is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.

We will provide appropriate notice of material changes to this privacy policy.