New Do your translations speak to AI as well as the original? · Discover
Livada.io
Legal

Privacy Policy

Livada Cockpit · Last updated: 25 May 2026

Data controller

Florin Livada, sole trader — SIRET 44198112300025 — Castellane (04120, France)
GDPR contact: contact@livada.io

1. Preamble

Livada Cockpit is a SaaS tool for businesses (hotels, restaurants, spas, healthcare, legal and accounting professionals, shops and services) to manage customer reviews from Google Business Profile, Booking.com, TripAdvisor, Trustpilot, Pages Jaunes, Doctolib, and similar platforms.

This policy explains what data we collect, for what purpose, how long we keep it, and what your rights are.

2. Personal data collected

2.1 Business customer data (subscriber)

DataPurposeLegal basis
EmailAccount + billing + supportPerformance of the contract
Name + company nameBillingLegal obligation
IP addressSecurity + auditLegitimate interest
Google OAuth tokenPublish replies on GBPExplicit consent
Licence key + WP URLAPI authenticationPerformance of the contract
Past replies (Brand Voice)AI few-shot learningExplicit consent

2.2 Reviewer data (collected reviews)

Cockpit collects the public reviews left by your customers on connected platforms (username, rating, text, date, source URL, detected language). We never collect private emails, postal addresses, phone numbers, banking data, or identifying medical data.

3. Purposes of AI processing

Cockpit uses Gemini Flash (4-5★ reviews), Claude Sonnet (sensitive reviews or sensitive sectors), and GPT-4o-mini (exotic languages) to generate replies. The review text is sent to the selected model, then returned for validation.

The APIs used do NOT use the data sent to train their models ("no-training" configuration on our business accounts).

4. Hosting and sub-processors

Sub-processorServiceLocation
CloudflareWorkers + D1 + PagesEurope (FR preferred)
Lemon SqueezyPayment + billingEU + USA — GDPR
BrevoTransactional emailsFrance 🇫🇷 — GDPR-native
Google AIGemini — AI generationEurope multi-region
AnthropicClaude — AI generationUSA — DPA + no-training
OpenAIGPT — AI generationUSA — DPA + no-training

No data is stored in China, Russia, or any country without an EU-equivalent agreement.

5. Retention period

  • Active customer account: for the duration of the subscription
  • Data after cancellation: 30 days, then permanent deletion
  • Invoices: 10 years (statutory tax obligation)
  • Server logs: 90 days
  • Collected reviews: 24 months, or deletion on request
  • OAuth tokens: until revoked by the customer

6. Your GDPR rights

In accordance with the GDPR (EU 2016/679), you have the following rights:

  • Access: obtain a copy of all your data
  • Rectification: correct inaccurate data
  • Erasure ("right to be forgotten"): deletion of account + data
  • Portability: JSON export of your reviews and configurations
  • Objection: refuse processing based on legitimate interest
  • Withdrawal of consent at any time

To exercise these rights: email contact@livada.io with proof of identity. Response within 30 days.
You may lodge a complaint with the CNIL.

7. Security

  • TLS 1.3 encryption for all communications
  • At-rest encryption of Cloudflare D1 data
  • No passwords stored in plain text
  • GDPR / AI Act audit logs for all AI actions
  • No commercial sharing of data with third parties

8. Sector-specific rules

For customers in the healthcare, legal, and accounting sectors, Cockpit applies enhanced compliance rules automatically injected into AI prompts:

  • Healthcare: no medical information of any kind allowed in public replies (GDPR art. 9)
  • Legal: no promise of judicial outcome allowed (Bar Association)
  • Accounting: no personalised public advice allowed (Ordre des Experts-Comptables)

9. Changes

Material changes will be notified by email to active customers 30 days before they take effect. The version in effect is always available at https://livada.io/en/legal/privacy.

Florin Livada — Castellane (04120) — SIRET 44198112300025 — contact@livada.io