Legal
Privacy Policy
How Livy collects, uses and protects personal information, and the choices and rights you have.
Updated 5 October 2026
1. Who is responsible for your information
Livy Technologies Limited (company number 17356112) is the controller of personal information used to run our website, early-access list and business, and to manage accounts and client relationships. Our registered office is 66 Paul Street, London, England, EC2A 4NA. For privacy enquiries or to exercise your rights, email hello@livy.com.
This policy covers website visitors, early-access subscribers, app users and people whose information is supplied in connection with our services. It describes our current website and account features and, separately, the processing needed when an accountancy engagement begins. A future feature being described here does not mean it is already available.
Where we process information solely on a business client’s instructions, the client is the controller and its privacy notice also applies. We will agree appropriate processor terms for that work.
2. Information we collect and where it comes from
For early access, we collect the email address you submit, the signup date, the signup source and a record of your consent to launch updates and an invitation. Our systems may also process technical request information, such as IP address, browser details, timestamps and error or security logs, to deliver and protect the service.
If you create an app account, we process account identifiers, contact and sign-in information, information you add to your business profile and records of your use of account features. If you contact us, we keep the information you give us and our correspondence.
When an agreed accountancy service starts, relevant information may include identity and verification records, director and beneficial-owner details, tax identifiers, invoices, receipts, transactions, bank details, payroll and employment records, returns and correspondence with authorities. The information required depends on the service in your engagement letter.
We obtain that information from you, people you authorise, your business or employer, an outgoing accountant and connected services you authorise. We may also receive it from HMRC, Companies House’s public register and identity-verification providers where needed for the agreed work or legal checks. We will explain new sources or uses when introduced.
Do not send sensitive information we have not requested. Where a service requires special-category information, such as health information for payroll, we must identify an applicable additional legal condition and explain the processing before it begins.
3. Why we use information and our lawful bases
- Early-access updates and invitations: your consent. Joining is optional, and you can withdraw consent at any time. We do not treat joining the list as consent to unrelated marketing.
- Providing services to you as an individual or sole trader: taking steps at your request before entering a contract and performing our contract with you.
- Managing a company client’s account and providing its agreed services: our legitimate interests in delivering the service and communicating with its authorised contacts. A company’s contract is not, by itself, a contractual lawful basis for processing every employee’s data.
- Answering enquiries and managing business relationships: our legitimate interests in responding to people and running the business, or pre-contract steps where you are seeking a service for yourself.
- Security, troubleshooting and preventing misuse: our legitimate interests in keeping accounts, information and systems secure and reliable.
- Legal checks, required records and lawful disclosures: compliance with applicable legal obligations, including tax and anti-money laundering requirements where relevant.
- Complaints and legal claims: compliance with applicable legal duties and our legitimate interests in investigating concerns, putting mistakes right and establishing, exercising or defending legal claims.
Where we rely on legitimate interests, we consider the necessity of the processing and its impact on your rights. We do not use that basis where your interests and rights override ours.
An email address is necessary to join the early-access list. Account details are necessary to provide an account. Identity, financial and other records may be required by law or by the agreed service; if you do not provide them, we may be unable to act. We will explain what is required when requesting it.
4. Who receives information
Access is limited to people and organisations that need information for the purposes above. We use Google Cloud and Firebase for infrastructure, account authentication and data storage. Hosting, communications, security and professional support providers may process relevant information on our behalf under appropriate contractual safeguards.
For agreed accountancy services, recipients may also include HMRC, Companies House, authorised banking or verification providers, your authorised representatives or a replacement accountant. Information filed on a public register may become public. We may disclose information to advisers, insurers, courts or authorities when necessary for legal obligations or claims.
We do not sell personal information. Before introducing integrations that change how your information is used or shared, we will update the relevant notice and obtain any permission required.
5. International transfers and security
Cloud services can involve processing or support access outside the UK. Before making a restricted transfer, we must establish an appropriate legal mechanism, such as UK adequacy regulations or approved contractual safeguards, and carry out any required assessment. You can request information about the countries involved and a copy of relevant safeguards, with confidential details removed where necessary.
We use access controls and other technical and organisational measures appropriate to the information and risks. No online service can guarantee absolute security. Keep account credentials secure and report suspected unauthorised access promptly.
6. How long we keep information
We keep information only for as long as needed for its purpose and relevant legal obligations. Retention depends on the type of record, the relationship, applicable statutory requirements and whether there is an unresolved complaint or claim.
- Early-access records: while we operate the list and need to send the updates you requested. On withdrawal, we stop those messages and delete or minimise the signup record, except for limited evidence needed to record the withdrawal or handle a complaint.
- Account and enquiry records: while needed to operate the account, resolve the enquiry and address any resulting obligations or dispute. Closing an account does not automatically require deletion of records retained on another lawful basis.
- Client records: for the applicable accounting, tax and legal record-keeping periods, taking account of the relevant financial year, filing period and any investigation or claim. The engagement documentation will explain the retention arrangements for the services you use.
- Security logs and backups: for the operational period needed to investigate incidents and recover systems, with deletion through the relevant log and backup lifecycle.
Records needed for an active legal matter may be retained until it is resolved. We then delete or anonymise information when there is no continuing lawful reason to retain it.
7. Cookies and device storage
The landing page does not currently include advertising or analytics cookies. We use the information submitted through the early-access form to process that request.
The app uses authentication-related device storage to keep you signed in. These functions are needed to provide the account features you request. If we introduce optional analytics or advertising technologies, we will explain them and obtain consent where required before using them.
8. Automation
The early-access signup records your request automatically; it does not make a decision with a legal or similarly significant effect on you. The website and account features covered by this draft do not make such decisions solely by automated means.
Before introducing accountancy features that make significant automated decisions, we will explain the information used, how the decision is made, its effects and the applicable safeguards, including how to obtain human intervention and challenge a decision. We will update this policy to reflect the actual service.
9. Your rights and choices
Depending on the circumstances, you can ask us to access or correct your personal information, erase it, restrict its use or provide a portable copy of information you supplied. Some rights have exceptions, including where we must keep records by law.
Your right to object: you can object to processing based on legitimate interests for reasons relating to your circumstances. You can always object to direct marketing, and we will stop using your information for that purpose.
Where processing relies on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. You can withdraw from early-access updates by emailing hello@livy.com or using an unsubscribe option in the messages we send.
Contact us to exercise a right; you do not need to use legal language or a particular form. We may need proportionate information to verify identity or clarify the request. We normally respond within one month, subject to extensions or permitted pauses under applicable law, and will explain any delay or refusal. Requests are normally free of charge.
10. Concerns and complaints
You can raise a concern about how we handle personal information using our Complaints procedure. You do not need to be a client to complain, and raising a complaint is free.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator. Its telephone number is 0303 123 1113 and its postal address is Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. The ICO generally asks that you give the organisation an opportunity to address the concern first.
11. Updates to this policy
We will update this policy as our services and processing change and show the revision date above. Where a change materially affects how we use your information, we will bring it to your attention before the new processing begins where required. A policy update does not itself provide consent for a new use of your information.