Back to homepage

Privacy Policy

This privacy policy explains how we process personal data in connection with the Livioris website and service (registration, login, use of the application).

Controller (Art. 13(1)(a) GDPR)

BYOM AS, represented by Karin Gutenbrunner Byom (Daglig leder), Skjoldenveien 9, 1832 Askim, Norway. Org. no.: 937 698 208. Email: karin@byom.com. Phone: +47 473 82 740.

1. Data protection at a glance

General information

The following notes give a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified.

2. Data collection on this website

What data is collected?

On registration: email address, password (stored hashed), optional name. On use: login data, content you enter (clients, appointments, protocols, etc.), technical log data (IP address, timestamp, actions without client content).

3. Purpose and legal basis

Purpose: provision of the service, contract performance, technical stability and security. No sharing for marketing purposes. Legal bases: contract (Art. 6(1)(b) GDPR) for registration and use; legitimate interests (Art. 6(1)(f) GDPR) for technical logs and security measures; consent (Art. 6(1)(a) GDPR) where explicitly obtained. Livioris processes all personal data in accordance with the GDPR and Austrian data protection law (DSG 2018).

4. Confidentiality

As a platform for life and social counselors, Livioris is subject to particularly strict data protection requirements. All client data is stored encrypted and is subject to statutory confidentiality obligations under the Austrian Trade Regulation Act (GewO § 119 para. 4). Livioris processes personal data on behalf of users as a processor pursuant to Art. 28 GDPR. During registration, a data processing agreement (DPA) pursuant to Art. 28 GDPR will be presented for your active confirmation. The current DPA can be accessed at any time at /avv.

5. Retention periods

Account data: as long as your account exists and thereafter only where legal retention obligations apply. Technical logs (IP, timestamps): automatically deleted after 90 days. Invoicing and billing data: 7 years (BAO § 132). Counseling content entered by you: until deletion by you or deletion of your account — no permanent storage beyond your use. Note for life and social counselors: the Austrian Federal Ministry documentation guidelines recommend a minimum retention period of 10 years for counseling documentation. This obligation rests with the counselor, not with Livioris as the software operator.

6. Your rights

You have the following rights under Art. 15–22 GDPR at any time: access to your stored personal data, its origin, recipients and purpose of processing; rectification of inaccurate data; erasure (right to be forgotten); restriction of processing; data portability; objection to processing. Requests by email to: karin@byom.com.

7. Cookies and tracking

Livioris uses technically necessary session cookies required for the operation of the application (authentication, language selection). Additionally, Sentry (Functional Software Inc., USA) is used for error monitoring and service stability. Sentry processes technical error data such as stack traces and anonymized usage data. No advertising trackers or marketing cookies are used. Legal basis for Sentry: legitimate interest (Art. 6(1)(f) GDPR) in technical stability and error diagnosis. Third-country transfer: Sentry Inc. based in the USA — data transfer on the basis of standard contractual clauses (SCC per Art. 46 GDPR).

8. Notifications

Livioris offers an in-app notification feature. Purpose: information about appointments, client assignments, milestones (e.g. practice hours). Recipients: only you as the logged-in counselor. Retention: until manual deletion by you or account deletion. Optional: email notifications (only with explicit consent via Settings). Legal basis: Art. 6(1)(b) GDPR (contract performance) for in-app notifications; Art. 6(1)(a) GDPR (consent) for email notifications. Metadata: notifications contain no personal client data, only IDs (e.g. appointment ID, client code).

9. Service providers and processors

Livioris uses the following service providers to operate the platform:

Render Inc. (USA): hosting of server, database, and web frontend, server location Frankfurt (Germany, EU). DPA in place. Third-country transfer: standard contractual clauses under Art. 46 GDPR and the EU-US Data Privacy Framework under Art. 45 GDPR (Render certified since January 6, 2025).

Supabase Inc. (USA): database and authentication, data location eu-west-1 (Ireland, EU). DPA in place. Third-country transfer: standard contractual clauses under Art. 46 GDPR.

Brevo (Sendinblue SA, France, EU): transactional email delivery. DPA in place. Brevo itself is based within the EU. Whether and which sub-processors Brevo uses outside the EU is currently under review (UNKNOWN: research needed, complete sub-processor list still pending).

Sentry (Functional Software Inc., USA): error monitoring and stability tracking, no client content affected. DPA in place. Third-country transfer: standard contractual clauses under Art. 46 GDPR.

Stripe Payments Europe, Ltd. (Ireland, EU) and Stripe Inc. (USA): payment processing and subscription management, PCI-DSS certified. DPA in place. Third-country transfer: standard contractual clauses under Art. 46(2)(c) GDPR (Module 2) and the EU-US Data Privacy Framework under Art. 45 GDPR.

Google Ireland Ltd. or Google LLC (USA): OAuth login and optional Google Calendar synchronization (see section 11). For OAuth login: processing by Google Ireland Ltd. within the EU, no third-country transfer. For calendar synchronization: Google LLC is certified under the EU-US Data Privacy Framework, transfer under Art. 45 GDPR. With business Google accounts (Workspace), Google acts as a processor under Art. 28 GDPR, DPA in place. With private Google accounts (e.g. gmail.com), Google acts as an independent controller under its own terms, no DPA with BYOM AS.

OVH SAS (France, EU): management of encryption keys (key management service) to protect your personal data stored with Livioris. OVH has no access to decrypted content. Data location France (EU), no third-country transfer.

GitHub Inc. (Microsoft, USA): source code version control. No client data in the code repository, no personal data involved.

All service providers are contractually obliged to process your data exclusively according to our instructions and in compliance with GDPR. No sharing with third parties for marketing purposes.

10. Use of AI (Artificial Intelligence)

Livioris uses AI-powered features to improve user experience and support development and quality assurance. AI use includes: code generation and review (GitHub Copilot, OpenAI/Anthropic APIs) – exclusively for development, no client data affected. Documentation and text suggestions (optional, only on user request) – processing is pseudonymized, no retention by AI providers (zero-data-retention models where possible). Purpose: efficiency, error reduction, quality assurance. No automated decisions about client data or counseling content. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) for internal development; consent (Art. 6(1)(a) GDPR) for optional text suggestions. Note: from summer 2026 stricter transparency requirements apply for AI use (AI Act). We will keep you informed of changes.

11. Google Calendar synchronization

Livioris offers optional synchronization with Google Calendar to simplify your daily practice management. There is no integration with Google Drive.

Livioris can create and update appointments (e.g. client sessions) directly in your Google Calendar. Purpose: centralized appointment overview without duplicate entries. We use the restricted scope calendar.events, meaning Livioris only has access to calendar events created through this feature, not to your entire Google Calendar.

Data minimization: appointments appear in your Google Calendar only in pseudonymized form, showing the client's first name and the first letter of their last name together with a neutral label (e.g. "Appointment", "Online session") instead of the full name. Notes, diagnoses, the client's email address, and internal IDs are not transmitted.

If you import your private Google Calendar into Livioris, this import is used solely for your personal display within the application. Imported private appointments are not linked to client records and are not evaluated for content. When you fully import your private Google Calendar, appointments containing data about third parties may also be shown, for example if other people appear in your private calendar. This data is likewise used solely for your personal display and is not linked to client records or evaluated for content.

Legal basis: the connection between Livioris and your Google account is based on your consent, granted via the Google consent screen (OAuth 2.0) and by activating the corresponding calendar clause in our Terms and Conditions. For client data transmitted to your Google Calendar through this feature, you, as the counselor, are the controller within the meaning of Art. 4(7) GDPR. You are required to obtain and document the explicit consent of each affected client before activating this feature (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR). Livioris processes this data as your processor (Art. 28 GDPR), not as an independent controller.

Google's role: if you use a business Google account (Google Workspace), Google processes your data as a processor under Art. 28 GDPR, and a corresponding data processing agreement between Google and you is in place. If you instead use a private Google account (e.g. gmail.com), Google processes your data as an independent controller under its own consumer terms; in this case, no data processing agreement exists between Livioris and Google for the calendar data processed by Google. Both types of accounts are permitted with Livioris.

Revocation: you can revoke Livioris's access to your Google account at any time at https://myaccount.google.com/permissions. After revocation, Livioris can no longer access your Google Calendar. Entries already created in your Google Calendar remain until you delete them yourself.

No AI training: your Google Calendar data is not used for AI or machine learning training.

Third-country transfer: processing is carried out by Google Ireland Ltd. or Google LLC (USA). Google LLC is certified under the EU-US Data Privacy Framework, so the transfer is based on an adequacy decision of the European Commission (Art. 45 GDPR). This applies regardless of whether you use a private or a business Google account.

Complaint to supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. Competent authority for the controller: Datatilsynet (Norway), https://www.datatilsynet.no. For users based in Austria: Austrian Data Protection Authority (DSB), https://www.dsb.gv.at.


Source: Regulation (EU) 2016/679 (GDPR), EUR-Lex. Not legal advice.