livewells A$699 a month excl. GST

Sub-processors and service providers

Version: 1.0 Effective: 11 October 2026 Version date: 11 October 2026

Contents
  1. Sub-processors (Customer Content)
  2. Service providers (account and billing data)
  3. Threat data
  4. Local data sources
  5. Sign-in
  6. Changes

These are the service providers that handle data for livewells. livewells is a hosted service, so some of them handle your Customer Content. This is the links you submit, and the video, reports and network logs of your sessions.

We hold your Customer Content in our role of processor. The providers in the first list are therefore sub-processors that we appoint for you in clause 5 of the Data Processing Agreement. We hold account and billing data, for example your work email, in our role of controller. The provider in the second list acts on our instructions. We keep the list short.

Sub-processors (Customer Content)

Cloudflare

  • What it does for us: hosting for the app and the API. It runs the session browsers. It stores Customer Content and account records. We encrypt the session files of each organisation with a key made for that organisation.
  • Data: Customer Content, account and audit records, and website request logs (IP address, browser type).
  • Location: we ask Cloudflare to store Customer Content in Oceania using a location hint. The hint is set on our R2 buckets, our D1 database and our Durable Objects. A hint is a request, not a guarantee. We do not set a location for session containers, which run in Cloudflare locations that we do not choose. Those locations can be in the countries where Cloudflare operates, including outside Australia. Cloudflare can handle the account, the control systems and the logs in the United States.

The transfer terms for Customer Content are in clause 6 of the Data Processing Agreement. A site that an Analyst opens is the destination of the instruction of the Customer, and it is not listed here. No enrichment provider receives data. livewells does its enrichment in its own service, with the two local data sources named below.

Service providers (account and billing data)

Stripe

  • What it does for us: checkout, billing and invoices.
  • Data: billing contact details, the Entra tenant identifier of the purchaser, the plan, and the status of the subscription. Stripe collects card details directly, and they do not go to us.
  • Location: the United States, and other countries in which Stripe operates.

Threat data

We hold de-identified threat data from confirmed-malicious cases in a store on Cloudflare that is apart from Customer Content. It is not Customer Content, and Cloudflare is the only provider that holds it. If we supply a threat feed, a recipient of it receives Threat Data only, and not Customer Content.

If we use another provider to train detection models, we list it on this page before it receives Threat Data. An Administrator can exclude all cases from threat data. The Analyst who ran a case, or an Administrator, can exclude that case. Each can do so whenever they wish (subscription terms clause 2.10). After an exclusion we put none of the excluded cases in a new export or a new training run.

Local data sources

We receive these sources in the form of databases that we store and search ourselves. Nothing about your sessions leaves our systems when we use them.

  • IPinfo Lite: the country and network for an IP address. IP address data powered by IPinfo (https://ipinfo.io). Licensed CC BY-SA 4.0.
  • abuse.ch (URLhaus and ThreatFox): lists of known malicious links, domains and IP addresses.

Sign-in

Microsoft Entra ID. Your Analysts sign in with your own Microsoft Entra ID. Microsoft is your identity provider in your agreement with Microsoft, and not our service provider. We receive the work email, and the tenant and user identifiers that Microsoft sends when a person signs in.

Changes

We publish a change to this list before a provider begins to handle your Customer Content or account data. We also notify the contacts on your Subscription by email at least 30 days before a provider begins to handle Customer Content. For an emergency replacement of a provider, we notify them promptly. If you have a data-protection concern about a listed provider, raise it with us directly at support@livewells.io.

If you object to a new sub-processor on reasonable data-protection grounds, you can end the affected Subscription. You then receive a pro-rata refund of prepaid fees for the unused term. Questions, including questions about the Privacy Act 1988 (Cth), go to support@livewells.io.