WP Umbrella Logo

Privacy Policy

Updated on 23 July 2026

At Liven Studio, we prioritise transparency and data privacy. We only collect the personal data necessary to provide and improve our services, we never sell your personal data, we store it securely and only for as long as needed, and we give you full control over it (access, correction, deletion, withdrawal of consent). Below is our privacy policy, explaining how we process personal data in compliance with the GDPR and the French Data Protection Act.

1. Introduction

By using our website (www.wp-umbrella.com) and application (**https://app.wp-umbrella.com/**), you acknowledge that you have read and understood this Privacy Policy. LIVEN STUDIO (“we”, “us”) determines how your personal data is processed, in compliance with Regulation (EU) 2016/679 (“GDPR”), the French Data Protection Act No. 78-17 of 6 January 1978, and — for users established there — the UK GDPR.

2. Who is this policy for?

This Privacy Policy applies to: visitors of our website; registered users of the Application; customers who subscribe to WP Umbrella; people who contact us for support, inquiries or partnerships; and affiliates or business representatives engaging with us. It covers the processing for which LIVEN STUDIO acts as data controller. For the processing that LIVEN STUDIO performs as a processor on behalf of its customers (their sites’ and end-clients’ data), see our separate Data Processing Agreement (art. 14 below).

3. Data controller

The data controller is LIVEN STUDIO, a simplified joint-stock company (SAS) with a share capital of €2,353, registered with the Lyon Trade and Companies Register under no. 901 423 434, headquartered at 4 rue de la République, 69001 Lyon, France. Contact for any privacy question or to exercise your rights: support@wp-umbrella.com.

4. Purposes and legal bases

PurposeLegal basis
Technical management of the Application (maintenance, hosting, security, account management)Performance of a contract; legitimate interest (platform functioning, security, abuse prevention)
Customer management (orders, payments, renewals, pre-sales exchanges, support)Performance of a contract; legal obligation (billing records kept up to 10 years)
Customer loyalty and commercial prospectingLegitimate interest (developing and retaining our business)
Measuring satisfaction and improving the Application (feedback, surveys)Legitimate interest; consent where the survey processes personal data
Website management (security, contact forms, testimonials, analytics, newsletter)Legitimate interest; consent (required for analytics and newsletter)
Management of the affiliate program (tracking affiliates and commissions)Performance of a contract (affiliate terms)

5. Personal data we process as controller

We process only the data necessary for the purposes above.

PurposeData
Technical managementAccount data: email, first name, last name, API key (login by email/password or via Google); connection data: IP addresses, logs, device and login identifiers
Customer managementAccount data (first name, last name, email); order data (billing address, company name, order and renewal dates, payment, exchanges)
Loyalty and prospectingFirst name, last name, email, country
SatisfactionName, first name, email, last login date, OS, ratings and comments
Website managementConnection data (IP, logs, device/browser identifiers); contact-form data (name, email, message); testimonial data (name, photo, position, testimonial); newsletter email. Audience-measurement data is anonymised
Affiliate programAffiliate identity; referred customers; commission amounts

We do not process special-category (sensitive) data (e.g. health, religion, biometrics). If that ever changes, we will request explicit consent.

6. Retention periods

PurposeRetention
Account dataWhile the account is active; after 3 years of inactivity we email you and, absent a response, delete or anonymise the data
Connection / security logsA few weeks to months, as needed for security
Billing and order data10 years (financial and tax obligations)
Support data2 years after the last ticket closure
Prospecting / marketing contacts3 years from the last interaction (or until you unsubscribe)
Satisfaction feedbackUp to 10 years
Testimonials5 years after publication
Newsletter subscribers3 years after last engagement (with an opt-in renewal message before deletion)
Affiliate data10 years after the affiliate contract ends

7. Recipients and sub-processors

Your personal data is used by LIVEN STUDIO and may be shared with the service providers that help us run the website and Application as processors — in particular our host Scaleway (EU), our payment provider Stripe, our audience-measurement provider Google, and our affiliate-tracking provider FirstPromoter, together with our email and support tools. Each is bound to comply with the GDPR. The full, up-to-date list of processors is available on request at support@wp-umbrella.com. We may also disclose data to competent authorities where legally required.

8. Cookies and trackers

Our website uses cookies and similar trackers for audience measurement and marketing. Trackers that are not strictly necessary are placed only with your consent, which you can give or withdraw at any time via the cookie banner and its settings. Full details of the trackers used, their purposes and durations are set out in our separate Cookie Policy.

9. Security measures

We implement technical and organisational measures to protect your data against unauthorised access, loss, alteration and misuse, in particular: encryption, data in transit over TLS 1.2/1.3, and sensitive data (passwords, payment details, backups) at rest in AES-256; access controls, access strictly limited to authorised staff and providers, with multi-factor authentication for administrative access; and infrastructure security, firewalls and DDoS protection at our host, with regular vulnerability testing. In the event of a personal data breach affecting your data, we assess the incident, notify the CNIL within 72 hours where required, inform affected users where their data is at risk, and take corrective action. To report a concern: support@wp-umbrella.com.

10. Transfers outside the European Union

Data is processed within the European Economic Area (EEA) wherever possible. Where a recipient is located outside the EEA in a country without a European Commission adequacy decision, we frame the transfer with appropriate safeguards under art. 46 GDPR, principally the Standard Contractual Clauses, or rely on a valid adequacy mechanism such as the EU–US Data Privacy Framework where the recipient is certified.

11. Automated decision-making

We do not engage in fully automated decision-making that produces legal or similarly significant effects on you. We use automated processes for fraud prevention (via Stripe), but these are subject to human oversight: if a fraud or security flag affects your account, our team reviews it manually before any action.

12. Your rights

Under the GDPR (and the UK GDPR where applicable), you have the rights below. To exercise any of them, contact support@wp-umbrella.com; we respond within 30 days.

RightWhat it means
AccessObtain a copy of the personal data we hold about you
RectificationCorrect inaccurate or incomplete data (also editable in your account)
ErasureHave your data deleted where it is no longer necessary (subject to legal retention, e.g. tax records)
RestrictionAsk us to temporarily suspend processing (e.g. while an accuracy request is checked)
PortabilityReceive your data in a structured, machine-readable format (JSON or CSV)
ObjectionObject to processing based on legitimate interest (e.g. marketing)
Withdraw consentWithdraw consent at any time where processing is based on it (e.g. newsletter)
Post-mortem directives (France)Set instructions for what happens to your data after your death

13. Complaint

If you believe we have mishandled your data, please contact us first at support@wp-umbrella.com so we can resolve it quickly. You also have the right to lodge a complaint with a supervisory authority — in France, the CNIL (https://www.cnil.fr/fr/webform/adresser-une-plainte), or the data protection authority of your country (the full EEA list is available via the EDPB). UK users may contact the ICO (www.ico.org.uk).

14. Processing carried out as a processor (Data Processing Agreement)

When you use WP Umbrella to manage your clients’ sites, LIVEN STUDIO also processes personal data as your processor, on your documented instructions, for example the data contained in your sites, backups and support tickets. That processing is not governed by this Privacy Policy but by our separate Data Processing Agreement (DPA), which forms part of the contract (T&C art. 4) and is accepted on account creation. The DPA sets out the art. 28 GDPR obligations, sub-processors, international transfers and security measures.

15. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing or in the law. Substantial changes are notified by appropriate means; the “Updated on” date above always indicates the current version.