WP Umbrella Logo

Privacy Policy

Updated on 23 July 2026

At Liven Studio, we prioritise transparency and data privacy. We only collect the personal data necessary to provide and improve our services, we never sell your personal data, we store it securely and only for as long as needed, and we give you full control over it (access, correction, deletion, withdrawal of consent). Below is our privacy policy, explaining how we process personal data in compliance with the GDPR and the French Data Protection Act.

1. Introduction

By using our website (www.wp-umbrella.com) and application (**https://app.wp-umbrella.com/**), you acknowledge that you have read and understood this Privacy Policy. LIVEN STUDIO (“we”, “us”) determines how your personal data is processed, in compliance with Regulation (EU) 2016/679 (“GDPR”), the French Data Protection Act No. 78-17 of 6 January 1978, and — for users established there — the UK GDPR.

2. Who is this policy for?

This Privacy Policy applies to: visitors of our website; registered users of the Application; customers who subscribe to WP Umbrella; people who contact us for support, inquiries or partnerships; and affiliates or business representatives engaging with us. It covers processing for which LIVEN STUDIO acts as a data controller. Processing carried out by LIVEN STUDIO as a processor on behalf of its customers, including Personal Data contained in or processed through their websites, backups and related services, is governed exclusively by the Data Processing Agreement (DPA).

3. Data controller

The data controller is LIVEN STUDIO, a simplified joint-stock company (SAS) with a share capital of €2,353, registered with the Lyon Trade and Companies Register under no. 901 423 434, headquartered at 4 rue de la République, 69001 Lyon, France. Contact for any privacy question or to exercise your rights: support@wp-umbrella.com.

4. Purposes and legal bases

PurposeLegal basis
Technical management of the Application (maintenance, hosting, security, account management)Performance of a contract; legitimate interest (platform functioning, security, abuse prevention)
Customer management (orders, payments, renewals, pre-sales exchanges, support)Performance of a contract; legal obligation (billing records kept up to 10 years)
Customer loyalty and commercial prospectingLegitimate interest (developing and retaining our business)
Measuring satisfaction and improving the Application (feedback, surveys)Legitimate interest; consent where the survey processes personal data
Website management (security, contact forms, testimonials, analytics, newsletter)Legitimate interest; consent (required for analytics and newsletter)
Management of the affiliate program (tracking affiliates and commissions)Performance of a contract (affiliate terms)

5. Personal data we process as controller

We process only the data necessary for the purposes above.

PurposeData
Technical managementAccount data: email, first name, last name, API key (login by email/password or via Google); connection data: IP addresses, logs, device and login identifiers
Customer managementAccount data (first name, last name, email); order data (billing address, company name, order and renewal dates, payment, exchanges)
Loyalty and prospectingFirst name, last name, email, country
SatisfactionName, first name, email, last login date, OS, ratings and comments
Website managementConnection data (IP, logs, device/browser identifiers); contact-form data (name, email, message); testimonial data (name, photo, position, testimonial); newsletter email. Audience-measurement data is collected only with your consent, given via the cookie banner, and is pseudonymised; details of the trackers used are set out in the Cookie Policy.
Affiliate programAffiliate identity; referred customers; commission amounts

We do not intentionally collect or process Special Categories of Personal Data within the meaning of Article 9 GDPR for the controller purposes described in this Privacy Policy. Where such data is exceptionally processed and consent is the applicable legal basis, we will obtain the consent required by applicable law.

6. Retention periods

PurposeRetention
Account dataWhile the account is active; after 3 years of inactivity we email you and, absent a response, delete or anonymise the data
Connection / security logsA few weeks to months, as needed for security
Billing and order data10 years (financial and tax obligations)
Support data2 years after the last ticket closure
Prospecting / marketing contacts3 years from the last interaction (or until you unsubscribe)
Satisfaction feedback3 years from collection; thereafter kept only in anonymised, aggregated form for statistics
Testimonials5 years after publication
Newsletter subscribers3 years after last engagement (with an opt-in renewal message before deletion)
Affiliate data10 years after the affiliate contract ends

7. Recipients and sub-processors

Your personal data is used by LIVEN STUDIO and may be shared with the service providers that help us run the website and Application — in particular our application host Scaleway (EU), our website host Kinsta Inc. (USA — this transfer is framed as described in article 10 below), our audience-measurement provider Google, our affiliate-tracking provider FirstPromoter, and our email and support tools, each acting as our processor; and our payment provider Stripe, which acts as an independent controller for the processing of payment transactions and its own regulatory and fraud-prevention obligations (see Stripe’s privacy policy). Each is bound to comply with the GDPR.

8. Cookies and trackers

Our website uses cookies and similar trackers for audience measurement and marketing. Trackers that are not strictly necessary are placed only with your consent, which you can give or withdraw at any time via the cookie banner and its settings. Full details of the trackers used, their purposes and durations are set out in our separate Cookie Policy.

9. Security measures

We implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised access, loss, alteration, disclosure or misuse. These measures include, as appropriate, encryption of Personal Data at rest and in transit using industry-standard technologies, access controls, multi-factor authentication for privileged access, logging and monitoring, vulnerability management, backup and recovery measures, and infrastructure security measures. In the event of a personal data breach affecting your data, we assess the incident, notify the CNIL within 72 hours where required, inform affected users where their data is at risk, and take corrective action. To report a concern: support@wp-umbrella.com.

10. Transfers outside the European Union

Data is processed within the European Economic Area (EEA) wherever possible. Where Personal Data is transferred outside the EEA to a country for which no European Commission adequacy decision applies, we implement an appropriate transfer mechanism under Chapter V GDPR, including appropriate safeguards under Article 46 GDPR where applicable. Where the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914 are used, the applicable module and annexes are completed according to the actual roles of the parties and the relevant transfer. Where an adequacy decision or another valid adequacy mechanism applies, we may rely on that mechanism.

11. Automated decision-making

We do not engage in fully automated decision-making that produces legal or similarly significant effects on you. We use automated processes for fraud prevention (via Stripe), but these are subject to human oversight: if a fraud or security flag affects your account, our team reviews it manually before any action.

12. Your rights

Under the GDPR (and the UK GDPR where applicable), you have the rights below. To exercise any of them, contact support@wp-umbrella.com. We respond within one month; for complex or numerous requests this period may be extended by two further months, in which case we will inform you within the first month (art. 12(3) GDPR).

RightWhat it means
AccessObtain a copy of the personal data we hold about you
RectificationCorrect inaccurate or incomplete data (also editable in your account)
ErasureHave your data deleted where it is no longer necessary (subject to legal retention, e.g. tax records)
RestrictionAsk us to temporarily suspend processing (e.g. while an accuracy request is checked)
PortabilityReceive your data in a structured, machine-readable format (JSON or CSV)
ObjectionObject to processing based on legitimate interest (e.g. marketing)
Withdraw consentWithdraw consent at any time where processing is based on it (e.g. newsletter)
Post-mortem directives (France)Set instructions for what happens to your data after your death

13. Complaint

If you believe we have mishandled your data, please contact us first at support@wp-umbrella.com so we can resolve it quickly. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL (https://www.cnil.fr/fr/webform/adresser-une-plainte), or the data protection authority of your country (the full EEA list is available via the EDPB). UK users may contact the ICO (www.ico.org.uk).

14. Processing carried out as a processor (Data Processing Agreement)

When you use WP Umbrella to manage your clients’ sites, LIVEN STUDIO may process Personal Data as your processor, on your documented instructions. That processing is governed by the Data Processing Agreement (DPA), not by this Privacy Policy. The DPA sets out the applicable Article 28 GDPR obligations, including the processing instructions, sub-processors, international transfers, security measures, assistance obligations and deletion or return of Personal Data.

For the avoidance of doubt, where LIVEN STUDIO processes such Personal Data solely on behalf of the User and on the User’s documented instructions, LIVEN STUDIO does not determine the purposes and means of that processing as an independent controller; the applicable processing terms are set out in the DPA.

15. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing or in the law. Substantial changes are notified by appropriate means; the “Updated on” date above always indicates the current version. This policy is published in English, French and German; the English version is authoritative and prevails over any translation.