Snapshot 77767
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy policy WEBSITE PRIVACY POLICY EU-U.S. DATA PRIVACY FRAMEWORKS DATA PROCESSING ADDENDUM Data Controller and Representative Live Story Inc., with registered office at 68 Greene Street, New York, NY 10012, USA, email privacy@livestory.io (hereinafter referred to as "Live Story" or "Controller"), is the data controller. The representative of the Controller in the European Union is Live Story srl, with registered office in Milan (MI), via Pola 11, VAT number 10838690963, email privacy@livestory.io. Categories of Personal Data collected Navigation Data The navigation on the Site and the access to its services involve the acquisition of certain personal data related to your browsing, such as, for example, the IP addresses or domain names of the computers used by you to connect to the Site, the URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to the operating system and the computer environment used by you. These are information that are not collected to be associated with identified data subjects, but which by their very nature could, through processing and association with data held by third parties, allow the identification of such data subjects. Personal Data Provided Voluntarily by You The Controller processes the personal data voluntarily provided by you when you contact us, such as, for example, personal identification information and contact details. Cookies The Site uses so-called cookies. For more information about cookies and their use on the Site, please refer to the cookie section. Purpose, Legal Basis, and Retention Period Your personal data will be processed by the Controller for: # PURPOSE LEGAL BASIS RETENTION PERIOD A Site Navigation: to enable you to browse the Site and access its related services, particularly to derive anonymous statistical information about the use of the Site and the services offered, and to monitor their proper functioning. Legitimate Interest of the Controller. For the period necessary for the respective processing. B User Support: for the management and response to the requests you submit to us through the contacts provided on the Site. Performance of the contract or pre-contractual measures adopted at your request. For the period of time necessary to respond to your request. C Candidate Assessment: for the evaluation of spontaneous job applications submitted through the Site. Performance of the contract or pre-contractual measures adopted at your request. For 24 months from the collection of the data. D Event Participation: to enable your participation in events and webinars and to communicate any relevant circumstances regarding such events. Performance of the contract or pre-contractual measures adopted at your request. Until 30 days after the end of the webinar. E Compliance with Legal Obligations: for the fulfillment of legal obligations (particularly in civil and personal data protection matters). Fulfillment of Legal Obligations. For a maximum period of 10 years from the termination of the relationship. F Litigation and Prevention of Illicit Activities: for the defense or enforcement of a right of the Controller and/or for the investigation and prevention of fraud and other crimes or illicit activities. Legitimate Interest of the Controller. For the entire duration of the litigation, until the expiration of the terms for challenging actions. G Marketing: the sending - via email - of newsletters and other informative and promotional communications, invitations to special events, as well as market research and statistical surveys on Live Story's products and services. Your consent. Until your withdrawal of consent or, failing that, for 24 months from the time of collection. For technical reasons, your personal data will be deleted or anonymized within 2 months from the expiration of the aforementioned retention periods. Nature of Data Provision The provision of data in fields marked with an asterisk (*) for the purposes outlined in Article 3, letters from A) to F) above, is necessary for browsing the Site and accessing the requested services, and failure to provide such data will result in the inability to obtain the requested services. Conversely, the provision of data in fields not marked with an asterisk, while potentially useful for facilitating relations with the Controller, is optional, and their omission does not affect the obtaining of the requested services. Categories of Recipients of Personal Data and Data Disclosure For the pursuit of the purposes for which the data are collected, the Controller may rely on the following categories of subjects to whom the data may be communicated or who may become aware of it as data processors: IT service providers, such as internet service and cloud computing providers; subjects providing customer support activities; professional firms and other entities providing assistance, consultancy, and services of a legal, tax, accounting, financial-economic, technical-organizational, data processing, or communication nature; public authorities and supervisory and control bodies. The updated list of data processors is available upon specific request to the Controller through the methods indicated in paragraph 8. Solely for the aforementioned purposes, your personal data may also be known to internal figures of the Controller authorized to process them due to their respective duties. No data collected on the Site is subject to disclosure. Tranfers of Data to a Third Country and/or International Organization Your personal data may be transferred, for the purposes for which they are collected, to the United States of America, which is a country outside the European Union. The transfer of personal data to subjects located in the United States of America will take place exclusively under the standard contractual clauses adopted or approved by the European Commission and/or the European Commission's adequacy decision of 10-07-2023 on the adequacy of the level of protection of personal data with EU-US Data Privacy Framework (Articles 45 and 46, par. II, letters c and d of the Regulation). To obtain a copy of such data, you can contact the Controller as indicated in paragraph 8. Minors The Site and services are intended for the sale of products and services to adults. Therefore, the Controller does not knowingly collect personal data from individuals under the age of 18. If you access the Controller's services, you declare that you are of legal age. Social Network insights The Site also includes social links. These are links to social networks, such as LinkedIn, Twitter, and YouTube, which allow you to reach the respective social networks by clicking on the link. With the support of these tools, you can, for example, share content or recommend Site services on social networks. Following clicks on the link, the social network may collect data regarding your visit to the Site. As anticipated in the preamble, this privacy notice does not concern the processing of data by the social network on behalf of the data subject, for which you should refer exclusively to the privacy notice provided by the social network. Except in cases where you voluntarily share your data with the chosen social networks through clicks on social links, the Controller does not disclose or share any personal data with the social network. Rights of the Data Subjects In relation to the personal data provided by you, you have the right at any time: a) to request confirmation as to whether or not personal data concerning you are being processed and, if so, to access the personal data, the information referred to in Article 15 GDPR, and a copy thereof (right of access); b) to request the rectification of inaccurate personal data concerning you and the integration of incomplete data, always in relation to the purposes of the processing (Article 16 GDPR); c) to request the erasure of personal data in cases referred to in Article 17 GDPR, including the lack of necessity of the personal data for the purposes for which they are collected or processed, the withdrawal of consent (if no other legal bases exist), or objection to processing (if no legitimate reasons for processing prevail), the unlawful processing of data, deletion imposed by legal obligations, or in the case of information society services provided to minors; d) to request the restriction of processing in cases referred to in Article 18 GDPR, such as contesting the accuracy of the data or the lawfulness of the processing, where the controller no longer needs the data for processing purposes or in case of objection to processing; the restriction of processing entails that your personal data will be processed only with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of significant public interest of the European Union or of a Member State; e) to object to the processing of personal data in cases referred to in Article 21 GDPR, including processing based on the legitimate interest of the data controller or third parties or for marketing purposes; in case of objection, the Controller refrains from further processing the personal data, unless compelling legitimate grounds for processing override your interests, rights, and freedoms, or for the establishment, exercise or defense of legal claims; f) to request data portability where processing is based on your consent or on a contract with the Controller and is carried out by automated means; portability entails the right to receive or transmit your personal data to another controller in a structured, commonly used and machine-readable format (Article 20 GDPR). To exercise your rights, you can write to: privacy@livestory.io. Finally, we remind you that, if the conditions are met, you also have the right to lodge a complaint with the relevant Data Protection Authority as the supervisory authority according to the procedures provided by the relevant authority. Data Privacy Framework Effective as of February 24th, 2025 For all Services (except those Services listed as out of scope below) Live Story, Inc. comply with the EU-U.S. Data Privacy Framework (“Data Privacy Framework”) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal data transferred from the European Union, as applicable, to the United States in reliance on the Data Privacy Framework. Live Story has certified to the Department of Commerce that it adheres to the Data Privacy Framework Principles with respect to such data. If there is any conflict between the terms in this notice and the Data Privacy Framework Principles, the Data Privacy Framework Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit the Data Privacy Framework website. Data processed Live Story provides a no-code cloud-based software platform which permits its clients to create, deploy and manage layouts on a website and remote screens, incorporating content from multiple sources, including content generated by both clients and third parties on social media. In providing this, Live Story processes data from these personal data categories: From social media: Username, Post, Post’s metadata; Uploaded from Live Story’s clients: Images and videos. Purposes of data processing Live Story processes data submitted by its clients for the purpose of providing Live Story’s online services to its clients. To fulfill these purposes, Live Story may access the data to provide the services, to correct and address technical or service problems, to respond to clients support matters, or to follow instructions of the Live Story clients who submitted the data, or in response to contractual requirements. Inquiries and complaints If you believe Live Story maintains your personal data in one of the services within the scope of our Data Privacy Framework certification, you may direct any inquiries or complaints concerning our Data Privacy Framework compliance to privacy@livestory.io. Live Story will respond within 45 days. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, you may have the possibility to engage in binding arbitration through the Data Privacy Framework Panel. For more information on this option, please see Annex I of the EU-U.S. Data Privacy Framework Principles. In compliance with the EU-U.S. DPF , Live Story commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF . Third parties who may receive personal data Live Story uses a limited number of third-party service providers to assist us in providing its services to clients. These companies are: Amazon Web Services, MongoDB Atlas, Live Story Srl. Live Story maintains contracts with these third parties restricting their access, use and disclosure of personal data in compliance with our Data Privacy Framework obligations, including the onward transfer provisions, and Live Story remains liable if they fail to meet those obligations and we are responsible for the event giving rise to damage. Your rights to access, correct, delete, and limit the use of your personal data EU individuals have rights to access personal data about them, correct inaccuracies, delete their personal data, and to limit use and disclosure of their personal data. With our Data Privacy Framework self-certification, Live Story has committed to respect those rights. If you wish to exercise any of these rights, you may contact us at privacy@livestory.io. Choices and means to limit the use and disclosure of personal data If personal data covered by this Privacy Policy is to be used for a new purpose that is materially different from the purpose for which it was originally collected or subsequently authorized, or is to be disclosed to a non-agent third party in a manner not specified in this Policy, Live Story will provide you with the opportunity to choose whether to allow such use or disclosure of your personal data. Requests to opt out of such uses or disclosures should be sent to us at privacy@livestory.io. Certain categories of personal data, such as information regarding medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, are considered “Sensitive Information.” Live Story will not use Sensitive Information for any purpose other than for which it was originally collected or subsequently authorized by you, unless we have received your explicit and affirmative consent (opt-in). For more information, please visit: https://www.dataprivacyframework.gov/framework-article/5%E2%80%93DATA-INTEGRITY-AND-PURPOSE-LIMITATION. U.S. Federal Trade Commission enforcement Live Story’s commitments under the Data Privacy Framework are subject to the investigatory and enforcement powers of the United States Federal Trade Commission. Compelled disclosure Live Story may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Data processing addendum BETWEEN The entity that executed the Contract with Live Story as set out on the order form (hereinafter also referred to as "Controller") AND Live Story Inc., with registered office in 68 Greene Street, New York, NY 10012, USA, (hereinafter also referred to as "Processor" or "Live Story") (hereinafter also referred to jointly as the "Parties" or individually as the "Party") WHEREAS a) the Parties have entered into a contract for the provision of services in the performance of which the Processor will process, on behalf of the Controller, the personal data set out in Appendix 1; b) with this Agreement, the Parties intend to regulate their respective rights and obligations with respect to the protection of personal data in accordance with Article 28 of EU Regulation No. 2016/679. Now therefore the parties agree as follows 1. DEFINITIONS 1.1. The terms "data controller", "data subject", "personal data", "processing", "data processor", "personal data breach", "impact assessment", "supervisory authority" and "international organization" used in this Agreement shall have the meanings set out in the Regulation. 1.2. For the purposes of this Agreement, the terms set forth below, when capitalized, shall have the meanings set forth therein, it being understood that each defined term shall have both singular and plural meanings: a) "Agreement" or "DPA" means this Agreement according to GDPR Article 28 and the Appendices thereto; b) "Contract" means the contract entered into between the Parties referred to in premise a); c) "Data" means the personal data set out in Appendix 1; d) "Processing Duration" means the period of time that the Data is processed by the Controller set out in Appendix 1; e) "Applicable Privacy Legislation" means the Regulation, the laws applicable to the processing of personal data and the guidelines, codes of conduct and orders issued and from time to time approved by the Data Protection Authority and applicable to the Parties under this Agreement; f) "Regulation" or "GDPR" means the EU Regulation No. 2016/679. 2. OBJECT 2.1. Pursuant to article 28 of the Regulation, the Controller appoints the Processor, who accepts the appointment, as data processor for the processing of the Data carried out in execution of the Contract. 2.2. The Processor must process the Data only on the documented instructions of the Controller, unless required to do so by EU or national law to which the Controller is subject, in which case the Processor must inform the Controller of such legal obligation prior to processing. 2.3. In particular, the Controller entrusts to the Processor all - and only - the Data processing operations necessary for the full execution of the Contract according to the instructions provided by this Agreement. 2.4. Should the need arise for Data processing that is different and exceptional with respect to that normally carried out, the Processor shall inform the Controller in advance. 2.5. If the Controller requests one or more changes to the instructions given in this Agreement (also with respect to security measures), the Processor shall verify the feasibility of such variations and, if positive, shall agree with the Controller on such changes and on the further compensation due for the same. 3. OBLIGATIONS OF THE PROCESSOR 3.1. The Processor shall immediately inform the Controller if, in its opinion, an instruction violates the Regulation or other Italian or European Union provisions relating to the protection of personal data. 3.2. The Processor, upon request of the Controller, assists the latter in the procedures before the competent Supervisory Authority and the Judicial Authority in relation to the activities falling within its competence. 3.3. The Processor also assists the Controller in ensuring compliance with the obligations relating to the data protection impact assessment and any prior consultation with the Supervisory Authority. 3.4. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with its obligations under this Agreement and the Applicable Privacy Legislation by permitting and contributing to any review activities, including inspections, performed by the Controller or another party retained by the Controller. In any event, any inspection of the Controller shall be conducted: a) with prior written notice of at least 7 business days and during the Processor’s working hours, subject to the need to conduct the inspection for emergency reasons and after the Controller has given prior written notice to the Processor, and b) up to a maximum of once a year, with the exception of any further inspections that the Controller is obliged to carry out at the request of the Control Authority and/or pursuant to the Applicable Privacy Legislation. 4. OBLIGATIONS AND GUARANTEES OF THE CONTROLLER 4.1. The Controller represents and warrants that: a) the processing entrusted to the Processor complies with the Applicable Privacy Legislation and this Agreement; b) for the processing of the Data, there is an appropriate condition of lawfulness; c) the Data subject to the operations of the Processor is collected and transmitted in compliance with the Applicable Privacy Legislation and this Agreement and, in any case, is relevant and not excessive in relation to the purposes for which it has been collected and subsequently processed; d) the Data provided to the Processor do not belong to any particular category of personal data, nor do they relate to criminal convictions and offences or to related security measures. 4.2. The Controller is responsible for Data processing implemented through application procedures developed according to its specifications and/or through its own IT or telecommunications tools. 4.3. The Controller undertakes to communicate to the Processor any change that may be necessary in the Data processing operations. 4.4. In the event that the Controller performs the processing operations covered by this Agreement as a data processor on behalf of another data controller, the Controller warrants that it is authorized by the data controller to enter into this Agreement and that the latter complies with the instructions received from the said data controller. 4.5. It remains the sole responsibility of the Controller to comply with the obligations imposed on it by the Applicable Privacy Legislation in relation to the Data (including the obligations relating to information and, where applicable, consent of the data subject). 5. SECURITY MEASURES 5.1. The Processor undertakes to adopt adequate security measures for the processing operations for which they are responsible, in accordance with Appendix 3. 5.2. The Processor reserves the right to change the security measures, ensuring that such changes will not lead, in the performance of the Contract, to a reduction in the level of security. 6. PERSONS AUTHORIZED BY THE PROCESSOR 6.1. The Processor, within its own company structure, will identify the natural persons authorized to process the data. At the same time as the designation, the Processor shall be responsible for providing adequate written instructions to the persons authorized to process the data, in compliance with the provisions of the law and of this Agreement. 6.2. It shall be the responsibility of the Processor to ensure the persons authorized to process the data are bound to confidentiality or to an adequate legal obligation of confidentiality, also for the period following the termination of the relationship of collaboration with the Processor, in relation to the processing operations performed by them. 7. DATA TRANSFERS 7.1. The Controller expressly authorizes the Processor to transfer personal data to international organizations or third countries not belonging to the European Union, in compliance with Chapter V of the Regulation. 7.2. All Data transfers from the Controller to the Processor outside the European Union are subject to the terms of the Standard Contractual Clauses under Appendix 4. 7.3. Moreover, the Processor participates in and certifies compliance with EU-U.S. Data Privacy Framework. The Processor shall notify the Controller if the Processor makes a determination it can no longer meet its obligation to provide the same level of protection as is required by the Data Privacy Framework Principles. 8. SUB-PROCESSORS 8.1. By this Agreement, the Controller hereby grants general authorization to the Processor to have recourse to any additional data processors for the purpose of the Processing. 8.2. In the event that the Processor makes effective use of sub-processors, the Processor undertakes to select sub-processors from among those subjects whose experience, capacity and reliability provide sufficient guarantees to implement the appropriate technical and organizational measures, so that the processing meets the requirements of the legislation applicable pro tempore and guarantees the protection of the rights of the data subjects. The Processor also undertakes to enter into specific contracts, or other legal documents, with the sub-processors by means of which the Processor describes their duties in detail and requires such subjects to comply with the same obligations, with reference to the personal data protection Regulation, imposed by the Controller on the Processor pursuant to the Applicable Privacy Legislation, providing in particular sufficient guarantees to implement the appropriate technical and organizational measures, so that the processing meets the requirements of the Applicable Privacy Legislation. 8.3. The Processor agrees to notify the Controller of the addition or replacement of a sub-processor 15 days prior to such changes. The Controller shall have the right to object to such changes within 15 days of receipt of the Processor’s notice. 8.4. Without prejudice to the provisions of art. 12, if a sub-processor, appointed by the Processor pursuant to this article, fails to fulfil its data protection obligations, the Processor acknowledges that it retains full responsibility towards the Controller for the fulfilment of the obligations of the aforementioned sub-processor. 8.5. The Controller has authorised the use of the sub-processors and the related Data transfer indicated in Appendix 2. 9. EXERCISE OF RIGHTS BY THE DATA SUBJECT 9.1. In the event that the Processor receives requests from data subjects for the exercise of the rights recognized by the Regulation, it must: a. refrain from contacting the data subject; b. promptly notify the Controller in writing, enclosing a copy of the request; c. taking into account the nature of the processing, assist the Controller with technical and organizational measures appropriate to meet the Controller's obligation to respond to requests to exercise the rights of data subjects. 9.2. In particular, where applicable and in consideration of the processing activities entrusted to them, the Processor shall: a. allow the Controller to provide the data subjects with their personal data in a structured, commonly used and machine-readable format, as well as to transmit the data to another controller; b. allow the Controller to grant, in whole or in part, the rights of objection and restriction of processing. 10. BREACH OF PERSONAL DATA 10.1. The Processor undertakes, where possible within 24 hours of becoming aware of it, to inform the Controller of any breach or suspected breach of Data and to provide the fullest cooperation to the Controller as well as to the competent and involved Supervisory Authorities in order to comply with any applicable obligation imposed by the Applicable Privacy Legislation (e.g. notification of a personal data breach to the competent Supervisory Authority; possible communication of a personal data breach to the data subjects). 11. DURATION OF THE AGREEMENT AND DELETION OF PERSONAL DATA 11.1. This Agreement shall become effective upon stipulation of the Contract and shall remain in effect until terminated for any cause, subject to specific obligations which by their nature are intended to remain in effect. 11.2. Should the contractual relationship between the Parties terminate or become ineffective for any reason, this Agreement will also automatically terminate without the need for notice or revocation. 11.3. Upon termination of the Contract or, if earlier, upon termination of the Processing Period and, in any case, upon receipt of a specific written request from the Controller, the Processor shall delete the Data within sixty (60) days, respectively, from the date of termination of the Contract, from the end of the Processing Period or from the Controller's request, unless European Union or Member State law provides for the retention of the Data. 12. LIMITATIONS OF LIABILITY 12.1. Without prejudice to the mandatory provisions of the applicable law, in the event of a breach and/or non-fulfilment of the obligations of the personal data processing legislation from time to time in force specific to data processors and/or this Agreement, including cases of breach and/or non-fulfilment by a sub-processor, the Processor shall be liable within the limits of the provisions of the Contract (including the article “Limitation of Liability”). 13. APPLICABLE LAW AND EXCLUSIVE JURISDICTION 13.1. This Agreement shall be governed by and construed in accordance with the applicable law set forth in the standard contractual clauses attached and shall be subject to the exclusive jurisdiction of the Court identified in the standard contractual clauses attached. 14. GENERAL PROVISIONS 14.1. This Agreement, including its appendices, is incorporated by reference into the Contract. 14.2. If any condition, covenant or provision contained in this Agreement is found to be invalid or illegal, such invalidity or illegality shall not affect, invalidate or void the other remaining provisions thereof. 14.3. This Agreement is expressly intended to revoke and supersede any other contract or agreement between the Parties with respect to its subject matter. 14.4. In the event of any conflict between the provisions of this Agreement and the Contract, the provisions of this Agreement shall prevail with respect to data protection obligations. 14.5. Communications between the Parties for the purposes of this Agreement shall be in writing to the addresses listed in Appendix 1. 14.6. Any amendment to this Agreement shall be in writing and shall be duly signed by representatives of the Parties. 14.7. For transfers of Data under this Agreement from the European Union, the European Economic Area and/or their member states and Switzerland to countries which do not ensure an adequate level of data protection within the meaning of applicable data protection laws of the foregoing territories, to the extent such transfers are subject to such applicable data protection laws, the Standard Contractual Clauses set forth in Appendix 4 apply. © 2026 Live Story srl - VAT 10838690963 - All rights reserved. — Privacy policy — Cookie Policy Company Sustainability Careers Product How it works Integrations Contact Sales Resources Pricing Release Notes Customer Stories Documentation