livewells A$699 a month excl. GST

livewells privacy policy

Version: 1.0 Effective: 11 October 2026 Version date: 11 October 2026

Contents
  1. Who we are
  2. What livewells is, and what we hold
  3. Threat data from confirmed-malicious cases
  4. This website and the app
  5. Signing in
  6. What we collect, and why
  7. Where it is held
  8. How long we keep it
  9. How we protect it, and breaches
  10. Automated decisions
  11. Access, changes to your details and complaints
  12. Customers and the Data Processing Agreement
  13. If you are in the EU or the UK (GDPR)

Who we are

livewells is published by Maelstrom AI Pty Ltd (ACN 679 356 702), an Australian proprietary company. It is the trustee for the Maelstrom AI Holding Trust (ABN 61 633 823 792). This policy explains how we handle personal information in the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We follow the Australian Privacy Principles in this policy, if the Act applies to us or if it does not. Words like analyst, administrator and service have their ordinary meaning in this policy.

What livewells is, and what we hold

livewells is a hosted service for security teams. An analyst opens a suspicious link by hand in a disposable, sandboxed browser, and livewells records what the page loaded and did. Unlike software that you run on your own systems, livewells holds your data for you. That data is your Customer Content:

  • the links you submit;
  • the video of each session;
  • the report of the redirect chain, the domains and the IP addresses that the page contacted;
  • the network log; and
  • the IP context and reputation results that we add to the report.

We also keep an audit log of each run. The identity record in the log shows who started the run, when, and the outcome. This is account data. The link in each entry is Customer Content.

A hostile page can show or capture anything. This includes credentials that a phishing page displays or that an analyst types into it. The video and report keep what the page showed. The operator of a site that you open sees the traffic of the session and the Cloudflare network addresses.

For your Customer Content we are your processor. You decide why and how it is used, in the Data Processing Agreement. For your account and billing data we are a controller in our own right (Data Processing Agreement clause 3.2).

The analysts of your organisation can see your Customer Content. We give it to our sub-processors only to run the service. We do not make it public, share it with another customer, sell it, or use it to train a model. The one exception is the threat data described below, which is the only data we use to train a model.

We access your Customer Content for support only with your written permission, and we agree an end time with you in writing. We also access it to investigate abuse or a security incident. We access only the records that the investigation requires, and we will give you written notice promptly, unless the law or the investigation forbids it. Our operator console shows no links, reports or videos.

We encrypt the session files of each organisation (the video, reports, network logs and enrichment results) with a key made for that organisation alone. Your administrator can delete all of your Customer Content whenever the account is active, and we then destroy the key. On your written request, we delete all of your Customer Content. Cloudflare keeps point-in-time history of its databases for a limited period.

We reply to support email by the next business day, 09:00 to 17:00 Australian Eastern Time. This is a target, not a resolution time. Support is by email to support@livewells.io.

A link, or a page that an analyst opens, can contain personal information about other people. An example is an email address in a link or a name on a page. The video and the report can keep that information. We hold it for your organisation, and we delete it when your retention period ends or when you ask us to. We contact no one who is named in a link that a customer opened.

Threat data from confirmed-malicious cases

An analyst of a customer assesses a case, concludes in good faith that the link is malicious, and sets the verdict to malicious. We can then use de-identified data from that case. This is a secondary use, and it is on by default. The customer can exclude cases from it.

  • What we use: attacker indicators (domains, IP addresses and redirect chains, defanged), page structure, enrichment signals, the verdict label, the month of the session and the country of the exit, where known. Attacker indicators are part of threat data on purpose. We redact recipient identifiers first.
  • Cases we do not use: cases with a different verdict; video; a case that the customer excludes from threat data; and the cases of an organisation that has excluded all its cases.
  • What it holds: threat data holds no video and no recipient identifier. It holds no information about the customer or its staff. We remove the domains, addresses and identifiers of your organisation, and we do not keep a record that holds one. If an indicator identifies a person, we apply the rules for personal information to it.
  • Why: to train livewells detection models, and to supply a livewells threat feed if we offer one. We decide that purpose, and we are accountable for it in the Privacy Act 1988 (Cth). A recipient of the threat feed receives threat data only, and not Customer Content.
  • We do not sell customer content. We do not try to re-identify a person or customer, and we do not allow a recipient of the threat feed to do so. Each recipient must agree to that in writing before it receives threat data.
  • How to exclude cases: the administrator of your organisation can select "Exclude all cases from threat data" whenever they wish, in the app. The analyst who ran a case, or an administrator, can select "Exclude this case from threat data" whenever they wish. We do not use an excluded case. You can also write to support@livewells.io.
  • What happens to an excluded case: we delete the records that we hold from it at our next scheduled run, which is each minute. We put none of them in a new export or a new training run. Turning off the exclusion of all cases does not bring back the cases that you excluded before. Turning off the exclusion of one case lets that case join again, if its verdict is malicious. A verdict changed away from malicious also withdraws the record. Material in an earlier export or in a trained model stays, because it is de-identified.
  • We keep the raw video, network log and page content only for the retention period. Deleting a session, or ending a subscription, leaves the de-identified data in place unless the case is excluded.
  • A person named in an indicator can write to support@livewells.io. We answer that request ourselves, in our role of controller of threat data.

This website and the app

The website at livewells.io sets no cookies of its own. The website and the app load no analytics script of ours or of a third party in your browser. We use no tracking pixels or fingerprinting. The app sets two cookies of its own. The two are strictly necessary to sign you in:

  • a sign-in session cookie that lasts 8 hours at most and ends after 30 minutes without use; we store only a hash of its value, and signing out ends the session; and
  • a short-lived cookie that protects a sign-in while it happens.

The website and the app are served from the network of Cloudflare. Cloudflare processes standard request logs (IP address, browser type) to deliver and protect the service. It can set strictly necessary security cookies of its own. We do not enrich, resell or join that data to anything.

Signing in

Your analysts sign in with Microsoft Entra ID. An administrator of your organisation gives admin consent in Microsoft Entra ID to link your tenant. We receive the work email, and the Entra tenant and user identifiers that Microsoft sends us when a person signs in. We decide which organisation a person belongs to from the Entra tenant that signs the person in. We keep these identifiers with the audit log of the runs of that person.

What we collect, and why

If you contact us or buy a paid plan, we hold a small set of business-contact information. This is your name and work email. It also covers a work phone number and role where you give them. It covers the correspondence of our dealings, for example sales enquiries and support tickets. We collect it only to answer you and to deliver and support a paid plan. This includes keeping the business and tax records that we must keep.

If you do not give us this information, we cannot supply a paid plan to you. No law requires you to give us this information, but tax and company law require us to keep the records of a sale.

If a colleague gave us your details. Sometimes a customer names a colleague in the role of billing or technical contact, or adds a colleague in the role of analyst. If that is you, we hold your name, work email, role and Microsoft Entra identifiers. We receive them from your employer or from Microsoft for the purposes above, and this page is the notice of that. All of this policy, including your rights, applies to you in the same manner.

Support is by email to support@livewells.io.

We send marketing only with your consent, and each marketing message has an unsubscribe link. We send no marketing from billing data. We do not add you to a marketing list that you did not ask for.

Checkout happens on the pages of Stripe. Stripe collects your name, email and card details there, and card details do not touch our site or our systems. We receive your name, email, the plan you chose, the Entra tenant identifier of the person who bought it, and the status of the subscription. We email you a receipt for each payment, and an email about a payment that is declined. For a yearly subscription, we also email you a renewal reminder before each renewal. At the end of a subscription we delete or return this information on your request, except records that the law requires us to keep.

Where it is held

We keep this information in a short list of services that we control or engage to process data for us. The sub-processor list names each one, what it receives and where.

  • Cloudflare, for hosting, and for storing your Customer Content and your account records. We ask Cloudflare to store Customer Content in Oceania using a location hint. A hint is a request, not a guarantee. We do not set a location for session containers, which run in Cloudflare locations that we do not choose. Those locations can be in the countries where Cloudflare operates, including outside Australia. Cloudflare can handle the account, the control systems and the logs in the United States.
  • Stripe, for checkout and billing. Stripe operates in the United States and in other countries.

Microsoft is the identity provider that you choose for sign-in. It receives your sign-in request in its own terms and privacy statement.

Cloudflare and Stripe can process personal information outside Australia. We require each of them, by written contract, to protect the information. We rely on their data processing agreements, and on a transfer basis that suits your jurisdiction. The Data Processing Agreement gives the transfer terms for Customer Content. We disclose personal information only to these providers and, where the law requires, to a court or authority. We do not sell it.

How long we keep it

Customer Content: we keep it for the retention period. The default is 90 days. Your administrator can set it between 7 and 365 days. When the period ends, we delete the sessions, their files and the links held in the audit log. The default runs from the end of the session.

Your administrator can delete one ended session, or all of your Customer Content, and you can ask us to delete it. The audit log keeps records of retention settings, deletions and operator actions.

Commercial contact and billing information: we hold it for the life of the relationship, and then for the period that the law requires, for example tax and company-record duties. We then delete it. We delete or age out support tickets after a matter is closed and the retention requirement has ended.

How we protect it, and breaches

The data of each customer is kept apart from the data of all other customers. The session files of each organisation are encrypted with its own key. Access to the service is by Microsoft Entra ID sign-in. Our own staff sign in through Microsoft Entra ID, with further checks on the tenant and the sign-in, before they use the operator console. The operator console shows no links, reports or videos.

We follow the Notifiable Data Breaches scheme. Where the scheme requires, we notify the affected individuals and the Office of the Australian Information Commissioner (OAIC). This applies to a breach of your account and billing data.

For a breach that affects your Customer Content, we tell the customer without undue delay. We do so within 72 hours of when we become aware of the breach. We give it the facts that it requires. The customer has the direct relationship with the people affected. It decides if a statutory notice is required and makes the notice, unless it asks us to make it. This does not limit a duty that the law places on us.

The GDPR and UK GDPR protect some personal information in our account, billing and support records. For a notifiable breach of it, we notify the competent supervisory authorities within 72 hours of when we become aware of the breach. We notify affected people without undue delay where the risk to them is high. We keep an internal record of each breach, and we also record a breach that is not notifiable.

Automated decisions

We make no automated decisions that significantly affect your rights or interests. livewells shows signals, and a person judges each link.

Access, changes to your details and complaints

You can ask what personal information we hold about you, ask us to correct it, or withdraw consent. Email support@livewells.io. We respond within 30 days and at no charge. If we refuse a request to access or correct your personal information, we tell you why in writing and how to complain. You can ask us for a copy of this policy in another form at support@livewells.io.

If you are unhappy with how we handled your information, complain to us at support@livewells.io. We acknowledge a complaint by the next business day, and we tell you the outcome within 30 days. If you are not satisfied, you can complain to the OAIC at oaic.gov.au.

If your information is in the Customer Content of a customer, we send your request to that customer, because the customer decides how it is used.

Customers and the Data Processing Agreement

We handle Customer Content in the Data Processing Agreement in our role of processor. We hold account and billing data in our role of controller (Data Processing Agreement clause 3.2). The Data Processing Agreement is part of the subscription terms.

If you are in the EU or the UK (GDPR)

Where the GDPR or UK GDPR applies to you, excluding cases from threat data works in the same manner, and we use only de-identified data. We decide the purpose of that use. Maelstrom AI Pty Ltd (ACN 679 356 702) is the controller of the account, billing and support records in this policy. It is the trustee for the Maelstrom AI Holding Trust. It is the processor of Customer Content for the customer that submitted it.

We are an Australian company. We have not appointed an EU or UK representative, and if we appoint one we will name them here. You can contact us directly at support@livewells.io. It reaches the operator, and a message to it is a privacy request from the moment it arrives.

Legal bases. We process account, billing and support records because they are necessary to perform our contract with your company (Article 6(1)(b)). We also process them to answer you before a contract exists (Article 6(1)(b)). We process them to keep the business and tax records that the law requires (Article 6(1)(c)). We process security and edge logs, and ordinary business correspondence, based on our legitimate interests in running and protecting the services (Article 6(1)(f)). You can object to that processing whenever you wish.

We process threat data based on our legitimate interests in running a threat feed and training detection models (Article 6(1)(f)). These models protect people from malicious links. The data is de-identified, and you can object by writing to support@livewells.io. We rely on consent only for marketing messages (Article 6(1)(a)). We rely on no other consent on these sites. We make no automated decisions with legal or similarly significant effect.

Your rights. You have the rights of access, rectification, erasure, restriction, portability and objection about your personal information. Email support@livewells.io and we respond within one month, free of charge. Where we must keep something despite an erasure request, for example invoice records in tax law, we say so and delete the rest. You can also complain to the supervisory authority in your member state, or to the UK Information Commissioner's Office, and to the OAIC in Australia.

International transfers. We are in Australia, which does not hold an EU adequacy decision.

You give us the information directly. Where we give personal information to our processors, they hold it in their data processing agreements. Cloudflare and Stripe rely on the EU-US Data Privacy Framework. They use standard contractual clauses for fallback. The sub-processor list shows their locations and what each receives.

Your Customer Content is a different matter. We hold it in our role of processor, and you stay its controller. The Data Processing Agreement gives the terms, including the standard contractual clauses where the GDPR or UK GDPR applies to a transfer.