PRIVACY POLICY

LIVE AWARE Mobile Application, BLE Detection
Platform and Associated Services

Last Updated: 08 August 2026 – 08-08-2026

Version: 1.0

1. INTRODUCTION

This Privacy Policy (“Privacy Policy”) describes the privacy and data-processing framework applicable to the mobile applications, software, Bluetooth Low Energy (“BLE”) detection functionality, servers, dashboards, application programming interfaces, databases, administrative portals, websites and related services (collectively, the “Services”) provided by:

LIVE AWARE LTD
128 City Road
London
EC1V 2NX
United Kingdom

Registered in the United Kingdom
Company Number: 17360063

(“LIVE AWARE”, “Company”, “we”, “us” or “our”).

The Services may enable authorised organisations, administrators and users to detect, receive, record, analyse, transmit and otherwise process BLE signals, identifiers, broadcasts, telemetry and associated information from compatible devices located within detectable proximity of devices running or interacting with the Services.

Because BLE technology can detect signals transmitted by devices located nearby, information collected through the Services may relate not only to the authorised user of the Mobile Application but potentially to devices, equipment, assets or individuals located within the detection environment.

Accordingly, organisations and users deploying the Services must carefully assess their own privacy, employment, surveillance, telecommunications, data-protection and other legal obligations before enabling BLE detection.

By installing, activating, accessing, configuring or using the Services, the Customer and each authorised user acknowledges the nature of the Services and agrees to comply with this Privacy Policy and all applicable laws.

Nothing in this Privacy Policy excludes, restricts or waives any right, responsibility or liability that cannot lawfully be excluded, restricted or waived.

2. IMPORTANT DISTINCTION BETWEEN LIVE AWARE AND THE CUSTOMER

The Services are technology tools.

The organisation, company, authority, institution or other entity deploying the Services (“Customer”) ordinarily determines:

  • where BLE detection takes place;
  • which authorised devices run the Mobile Application;
  • why BLE signals are detected;
  • what information should be collected;
  • what BLE identifiers are relevant;
  • which locations are monitored;
  • how information is interpreted;
  • whether detected identifiers are associated with individuals, assets or other records;
  • how long Customer-controlled information is retained;
  • who within the Customer organisation may access the information;
  • what actions are taken based upon detections;
  • whether information is exported;
  • whether information is combined with other datasets; and
  • the purposes for which information is ultimately used.

To the extent that the Customer determines the purposes and essential means of processing personal data, the Customer acts as the relevant data controller or equivalent responsible party under applicable privacy law.

Where LIVE AWARE processes Customer Personal Data solely on documented instructions from a Customer, LIVE AWARE may act as a processor or service provider.

LIVE AWARE may separately act as an independent controller in relation to information processed for its own legitimate business purposes, including account administration, security, fraud prevention, billing, compliance, service administration and protection of the Services.

The actual legal status of each party is determined by applicable law and the factual circumstances of the processing and cannot be altered merely by contractual terminology.

3. CUSTOMER RESPONSIBILITY FOR DEPLOYMENT

The Customer is responsible for determining whether its intended deployment and use of the Services is lawful.

The Customer must not assume that the availability of any feature means that use of that feature is lawful in every country, workplace, property, facility, public space or other environment.

The Customer is solely responsible, to the maximum extent permitted by applicable law, for establishing an appropriate lawful basis for Customer-controlled processing and for providing any notices, signage, disclosures, policies or consent mechanisms required by law.

This includes responsibility for assessing whether its use requires:

  • consent;
  • legitimate-interest assessments;
  • employee notices;
  • visitor notices;
  • workplace monitoring policies;
  • privacy notices;
  • contractual notices;
  • signage;
  • data-protection impact assessments;
  • security assessments;
  • union or works council consultation;
  • regulatory consultation;
  • parental or guardian consent;
  • access restrictions;
  • retention schedules; or
  • any other privacy or compliance measure.

4. BLUETOOTH LOW ENERGY DETECTION

The Mobile Application may use Bluetooth and BLE functionality available through the operating system of an authorised mobile device.

Depending upon configuration, operating system, permissions, deployment environment and detected devices, BLE-related information may include:

  • BLE advertisements;
  • broadcast packets;
  • advertised device names;
  • device identifiers;
  • manufacturer-specific data;
  • service UUIDs;
  • characteristic UUIDs;
  • beacon identifiers;
  • protocol information;
  • received signal strength indicators (“RSSI”);
  • estimated proximity;
  • transmission information;
  • timestamps;
  • detection frequency;
  • detection duration;
  • first-seen timestamps;
  • last-seen timestamps;
  • repeated detection events;
  • scanner/device identifiers;
  • installation identifiers;
  • site identifiers;
  • zone identifiers;
  • associated metadata;
  • diagnostic information;
  • application-generated identifiers; and
  • other technical information contained in or derived from BLE broadcasts.

BLE information may constitute personal data if it directly or indirectly identifies, relates to, singles out, tracks or can reasonably be associated with an identifiable individual.

Customers must therefore treat BLE detection data appropriately according to the context in which the Services are deployed.

5. PROXIMITY IS AN ESTIMATE

BLE signal strength is not a guaranteed measurement of physical distance.

RSSI and other Bluetooth characteristics may be affected by:

  • walls;
  • floors;
  • doors;
  • furniture;
  • people;
  • vehicles;
  • electronic interference;
  • antenna orientation;
  • transmission power;
  • hardware differences;
  • device settings;
  • environmental conditions;
  • signal reflection;
  • signal absorption;
  • software behaviour;
  • operating-system restrictions; and
  • other technical or physical factors.

Accordingly, proximity estimates, presence indicators and similar outputs must not automatically be interpreted as conclusive proof that a specific individual or device was present at an exact location, at an exact distance or for an exact duration.

Customers are responsible for determining the evidential weight, if any, that should be attributed to detection information.

6. INFORMATION THE SERVICES MAY PROCESS

Depending upon configuration, the Services may process categories of information including:

6.1 Account Information

This may include:

  • name;
  • username;
  • business email address;
  • telephone number;
  • organisation;
  • department;
  • job title;
  • account identifier;
  • authentication information;
  • role;
  • permissions; and
  • account preferences.

6.2 Mobile Device Information

This may include:

  • device type;
  • device model;
  • operating-system version;
  • application version;
  • device-generated identifiers;
  • installation identifiers;
  • language;
  • regional settings;
  • Bluetooth status;
  • permission status;
  • network information;
  • diagnostic information; and
  • application configuration.

6.3 BLE Detection Information

This includes the BLE-related information described elsewhere in this Privacy Policy.

6.4 Operational Information

This may include:

  • login records;
  • administrative actions;
  • configuration changes;
  • audit logs;
  • export actions;
  • API activity;
  • synchronization records;
  • server events;
  • security events;
  • error logs;
  • crash information;
  • application performance data; and
  • technical troubleshooting information.

6.5 Location-Related Information

The Services may infer approximate presence, zone, site or proximity information based upon where scanning devices are deployed.

Depending upon operating-system requirements and Customer configuration, the Mobile Application may also request permissions associated with Bluetooth, nearby devices or location.

Granting an operating-system permission does not necessarily mean that every technically accessible category of information is collected.

6.6 Customer-Provided Information

Customers may upload, enter, associate or integrate information with the Services.

LIVE AWARE does not control the nature of all information that Customers choose to upload, integrate or associate with BLE detections.

7. DETECTIONS INVOLVING THIRD-PARTY DEVICES

A significant characteristic of BLE technology is that a scanning device may receive broadcasts from compatible devices without the owner of the broadcasting device directly interacting with the scanner.

Customers acknowledge that detections may therefore involve third-party devices.

The Customer is responsible for determining whether collecting, storing, analysing or otherwise processing such information is permissible within its deployment environment.

The Customer must not intentionally use the Services to conduct unlawful surveillance, stalking, harassment, discrimination or unauthorised tracking.

8. CUSTOMER AS DATA CONTROLLER

Where the Customer determines why BLE or related information is collected and how that information will be used, the Customer generally acts as controller for that processing, subject to applicable law.

The Customer is responsible for:

  • establishing a lawful basis;
  • providing required privacy information;
  • respecting applicable data-subject rights;
  • responding to lawful requests;
  • establishing retention periods;
  • determining access permissions;
  • maintaining appropriate security;
  • controlling exports;
  • preventing unauthorised disclosure;
  • conducting required impact assessments;
  • maintaining required records;
  • ensuring accuracy where necessary;
  • implementing data minimisation;
  • ensuring purpose limitation;
  • investigating Customer-side incidents;
  • making Customer-side regulatory notifications where required; and
  • otherwise complying with applicable privacy legislation.

9. LIVE AWARE AS PROCESSOR

Where LIVE AWARE hosts or otherwise processes Customer Personal Data solely on behalf of the Customer, LIVE AWARE may act as processor.

Such processing should be governed by the applicable commercial agreement and, where legally required, a Data Processing Agreement.

LIVE AWARE will process processor-controlled Customer Personal Data in accordance with documented Customer instructions, except where otherwise required by applicable law.

10. STAND-ALONE AND ON-PREMISE DEPLOYMENTS

LIVE AWARE may offer deployments in which Customer Data is stored in a stand-alone, isolated or Customer-controlled on-premise server environment.

Where a deployment is genuinely configured so that Customer Data remains entirely within Customer-controlled infrastructure and is not transmitted to LIVE AWARE systems, LIVE AWARE may have no routine technical access to that Customer Data.

In such cases:

  • the Customer controls its infrastructure;
  • the Customer controls database access;
  • the Customer controls backups;
  • the Customer controls user permissions;
  • the Customer controls exports;
  • the Customer controls security configuration;
  • the Customer controls retention;
  • the Customer controls deletion; and
  • the Customer is responsible for operating and protecting the environment.

LIVE AWARE cannot be responsible for information to which it has no access or control, except to the extent responsibility is imposed by applicable law.

11. HOSTED AND CLOUD DEPLOYMENTS

Where the Customer uses a LIVE AWARE-hosted or cloud-connected deployment, Customer Data may be accessible to LIVE AWARE to the extent reasonably necessary for providing and supporting the Services.

Subject to applicable law and contractual restrictions, such access may occur for purposes including:

  • hosting;
  • storage;
  • synchronization;
  • backups;
  • maintenance;
  • troubleshooting;
  • technical support;
  • cybersecurity;
  • incident investigation;
  • fraud prevention;
  • abuse prevention;
  • integrity monitoring;
  • availability monitoring;
  • database administration;
  • disaster recovery;
  • enforcing contractual restrictions;
  • complying with law; and
  • protecting LIVE AWARE, Customers, users and third parties.

The Customer acknowledges that using a hosted environment necessarily requires certain technical processing of Customer Data.

LIVE AWARE personnel access to Customer Personal Data should be limited according to operational necessity and applicable access-control procedures.

12. CUSTOMER RESTRICTION ON DATA EXPORT

Unless expressly permitted by the Customer’s contract, internal policies and applicable law, authorised users must not export, copy, transfer, disclose, publish, transmit, extract, reproduce, scrape or otherwise remove protected detection information from the authorised environment.

In particular, users must not transfer detection information to:

  • personal email accounts;
  • personal cloud-storage accounts;
  • unauthorised USB devices;
  • unauthorised databases;
  • public websites;
  • social-media platforms;
  • messaging applications;
  • unauthorised third parties;
  • personal computers; or
  • other systems not approved by the Customer.

The Customer is responsible for establishing and enforcing appropriate internal controls.

13. CLOSED-ENVIRONMENT PRINCIPLE

Where the Services are deployed as a closed-environment system, information collected through the Services is intended to remain within that approved environment except where an authorised transfer is lawful and permitted.

Users must treat detection information as confidential operational information.

Users must not attempt to circumvent technical restrictions intended to prevent unauthorised export.

14. AUTHORISED USERS

The Customer is responsible for all persons to whom it grants access.

The Customer must ensure that authorised users:

  • are appropriately trained;
  • receive required privacy information;
  • understand confidentiality obligations;
  • use individual credentials where appropriate;
  • do not share passwords;
  • protect authentication devices;
  • promptly report suspected compromise;
  • access only information required for their role;
  • do not unlawfully export information; and
  • comply with Customer policies.

15. CUSTOMER ADMINISTRATOR ACCESS

Customer administrators may have broad access to information generated through their organisation’s deployment.

Depending upon permissions, administrators may be able to:

  • view detection records;
  • view account information;
  • view activity;
  • manage users;
  • configure devices;
  • configure sites;
  • view logs;
  • perform searches;
  • generate reports;
  • export authorised information;
  • change retention settings; and
  • delete information.

Users should therefore understand that information generated through a Customer-controlled account may be visible to authorised Customer administrators.

16. NO EXPECTATION OF PERSONAL PRIVACY WITHIN CUSTOMER BUSINESS ACCOUNTS

To the extent permitted by applicable law, authorised users should not treat a Customer-controlled business account as a private personal account.

Information created, generated or stored within the Customer’s organisational environment may be accessible to authorised Customer personnel.

Any monitoring of employees, contractors or other personnel remains subject to applicable law and is the Customer’s responsibility.

17. PURPOSES OF PROCESSING

Depending upon the deployment, information may be processed for purposes including:

  • operating the Services;
  • detecting BLE broadcasts;
  • recording detection events;
  • identifying authorised devices or assets;
  • determining approximate proximity;
  • analysing operational patterns;
  • maintaining security;
  • providing dashboards;
  • generating Customer-requested reports;
  • synchronising devices;
  • authenticating users;
  • maintaining accounts;
  • preventing fraud;
  • detecting misuse;
  • investigating incidents;
  • providing technical support;
  • debugging;
  • improving reliability;
  • maintaining backups;
  • recovering from failures;
  • maintaining audit trails;
  • enforcing agreements;
  • protecting legal rights;
  • complying with lawful requirements; and
  • other purposes instructed by the Customer where LIVE AWARE acts as processor.

18. LAWFUL BASES

Where LIVE AWARE acts as controller, the lawful basis used depends upon the particular processing and applicable law.

Possible lawful bases may include:

  • performance of a contract;
  • legitimate interests;
  • compliance with legal obligations;
  • consent, where applicable; and
  • other bases available under applicable law.

Where LIVE AWARE acts solely as processor, the Customer is responsible for determining the lawful basis applicable to Customer-controlled processing.

19. DATA MINIMISATION

Customers should configure the Services so that they collect only information reasonably necessary for the intended lawful purpose.

Customers should avoid collecting information merely because it is technically available.

20. PURPOSE LIMITATION

Information collected for one specified purpose should not subsequently be used for an incompatible purpose unless such further processing is lawful.

Customers are responsible for assessing any proposed secondary use of Customer Data.

21. ACCURACY

BLE detections and derived information can be affected by technical and environmental factors.

Customers must take reasonable steps to avoid treating uncertain technical data as incontrovertible factual evidence.

Where decisions materially affecting individuals are contemplated, Customers should independently assess accuracy, context and applicable legal requirements.

22. RETENTION

Retention periods may depend upon Customer configuration, contractual arrangements, technical requirements, backup schedules and legal obligations.

Customers should establish retention periods appropriate to their processing purposes.

LIVE AWARE may retain limited information where reasonably necessary for:

  • security;
  • backups;
  • dispute resolution;
  • fraud prevention;
  • legal compliance;
  • enforcing agreements; or
  • establishing, exercising or defending legal claims.

Where deletion is requested, information may remain temporarily in secure backup systems until overwritten or deleted according to applicable backup cycles, subject to law and contractual commitments.

23. SECURITY

LIVE AWARE seeks to implement technical and organisational measures appropriate to the nature and risk of processing under its control.

Such measures may include, where appropriate:

  • authentication;
  • role-based access;
  • encryption;
  • network controls;
  • logging;
  • access restrictions;
  • monitoring;
  • backup procedures;
  • vulnerability management;
  • software updates;
  • credential controls; and
  • incident-response procedures.

No electronic system is completely secure.

LIVE AWARE therefore does not warrant that unauthorised access, cyberattacks, software vulnerabilities, hardware failures or other security incidents can never occur.

24. CUSTOMER SECURITY RESPONSIBILITIES

The Customer is responsible for security matters within its control, including:

  • securing mobile devices;
  • protecting administrator accounts;
  • implementing appropriate passwords;
  • managing user access;
  • revoking former employees;
  • controlling physical access;
  • protecting on-premise servers;
  • maintaining supported operating systems;
  • installing updates;
  • protecting API credentials;
  • protecting exports;
  • configuring firewalls;
  • managing backups;
  • protecting network infrastructure; and
  • responding to Customer-side incidents.

25. LOST OR STOLEN DEVICES

Customers should promptly revoke access associated with lost, stolen, compromised or reassigned devices.

LIVE AWARE is not responsible for unauthorised access resulting from a Customer’s failure to appropriately secure credentials or devices, except to the extent such responsibility cannot lawfully be excluded.

26. PASSWORDS AND CREDENTIALS

Users must keep credentials confidential.

Users must not knowingly permit unauthorised persons to use their credentials.

The Customer remains responsible for managing accounts created under its organisational environment.

27. LOGGING AND AUDIT INFORMATION

The Services may maintain logs for purposes including:

  • cybersecurity;
  • accountability;
  • debugging;
  • support;
  • performance;
  • investigation;
  • compliance;
  • abuse prevention; and
  • service administration.

Users should not attempt to disable, manipulate or falsify security or audit logs.

28. COOKIES AND SIMILAR TECHNOLOGIES

Web interfaces associated with the Services may use cookies, local storage, SDKs, tokens or similar technologies.

Strictly necessary technologies may be used where permitted without consent to provide functionality requested by the user or for purposes such as authentication and security.

Where consent is legally required for non-essential cookies or similar technologies, LIVE AWARE will seek to provide an appropriate consent mechanism.

Users may be able to manage non-essential technologies through the applicable consent interface, browser or device settings.

The Services must not be interpreted as requiring users to waive statutory cookie or privacy rights where such waiver would be unlawful.

29. MOBILE SDKs AND SIMILAR TECHNOLOGIES

Mobile applications may use local storage, software development kits, operating-system APIs, authentication tokens and other technologies necessary to provide application functionality.

Some of these technologies may be functionally equivalent to cookies for applicable privacy-law purposes.

30. THIRD-PARTY SERVICE PROVIDERS

LIVE AWARE may engage appropriately selected third-party providers for services such as:

  • infrastructure;
  • hosting;
  • communications;
  • security;
  • monitoring;
  • support;
  • analytics;
  • authentication;
  • database services;
  • backups; and
  • other technical operations.

Where required, such providers will be subject to appropriate contractual and data-protection obligations.

31. SUB-PROCESSORS

Where LIVE AWARE acts as processor, subprocessors may be used subject to the applicable Data Processing Agreement and legal requirements.

Customers requiring specific subprocessor information should refer to the applicable contractual documentation.

32. INTERNATIONAL DATA TRANSFERS

Where personal information is transferred internationally, LIVE AWARE will seek to use a lawful transfer mechanism where required.

Customers operating self-hosted environments are responsible for transfers they independently initiate or configure.

33. DISCLOSURE REQUIRED BY LAW

LIVE AWARE may disclose information where reasonably believed necessary to comply with:

  • applicable law;
  • court orders;
  • warrants;
  • regulatory requirements;
  • lawful governmental demands; or
  • other legally binding obligations.

Where legally permitted and appropriate, LIVE AWARE may challenge requests believed to be unlawful, excessive or invalid.

34. PROTECTION OF RIGHTS AND SECURITY

Information may also be processed or disclosed where reasonably necessary and legally permitted to:

  • protect the security of the Services;
  • investigate fraud;
  • investigate abuse;
  • prevent cyberattacks;
  • protect users;
  • protect third parties;
  • enforce contractual rights;
  • establish legal claims;
  • exercise legal rights; or
  • defend legal claims.

35. BUSINESS TRANSACTIONS

If LIVE AWARE undergoes a merger, acquisition, financing, restructuring, insolvency, reorganisation or sale of assets, information may be disclosed or transferred as part of that transaction subject to applicable law.

36. CHILDREN

The Services are principally intended for organisational and professional deployment and are not designed as consumer services directed at children.

Customers must not intentionally configure the Services to process information relating to children unless they have determined that such processing is lawful and have implemented all safeguards required by applicable law.

37. SPECIAL CATEGORY OR SENSITIVE INFORMATION

Customers should not intentionally use BLE detections to infer sensitive characteristics unless such processing is specifically authorised, necessary and lawful.

Depending upon jurisdiction, sensitive information may include information concerning:

  • health;
  • disability;
  • race;
  • ethnicity;
  • religion;
  • political opinions;
  • trade-union membership;
  • genetics;
  • biometrics;
  • sexuality; or
  • other legally protected characteristics.

38. EMPLOYEE MONITORING

Where a Customer deploys the Services in a workplace, the Customer is solely responsible for evaluating applicable workplace-monitoring laws and employee privacy requirements.

Customers should not use the Services for covert employee surveillance where prohibited by law.

39. VISITORS AND THIRD PARTIES

Where BLE detection may affect visitors, contractors, customers or other third parties, the Customer is responsible for determining whether appropriate notice or other safeguards are required.

40. AUTOMATED DECISIONS

Unless expressly agreed otherwise, the Services should not be treated as a system intended to make legally significant decisions about individuals solely on the basis of automated BLE detections.

Customers contemplating automated decision-making are responsible for assessing applicable legal requirements and implementing appropriate safeguards.

41. HIGH-RISK USES

Unless expressly authorised in writing and appropriately assessed, Customers must not rely upon the Services as the sole basis for:

  • medical diagnosis;
  • emergency dispatch;
  • life-safety decisions;
  • criminal guilt determinations;
  • employment termination;
  • credit decisions;
  • insurance eligibility;
  • immigration decisions;
  • judicial decisions; or
  • other decisions where inaccurate detection could create serious consequences.

42. NO GUARANTEE OF DETECTION

LIVE AWARE does not guarantee that every BLE device within physical proximity will be detected.

Detection depends upon multiple factors outside LIVE AWARE’s control.

Devices may stop broadcasting, rotate identifiers, use unsupported protocols, disable Bluetooth, restrict background scanning or otherwise become undetectable.

43. FALSE POSITIVES AND FALSE NEGATIVES

The Customer acknowledges the possibility of:

  • missed detections;
  • duplicate detections;
  • incorrect associations;
  • delayed detections;
  • inaccurate proximity estimates;
  • stale records;
  • temporary signal loss;
  • identifier rotation;
  • signal collisions; and
  • detections originating beyond an assumed physical boundary.

Customers must take these limitations into account when using detection information.

44. NO WARRANTY AS TO IDENTITY

Detection of a device does not necessarily establish the identity of the person possessing or operating that device.

Customers must not assume otherwise without adequate independent verification.

45. USER PROHIBITIONS

Users must not use the Services to:

  • violate privacy laws;
  • unlawfully track individuals;
  • stalk or harass persons;
  • discriminate unlawfully;
  • circumvent security controls;
  • obtain unauthorised access;
  • export protected data without authority;
  • reverse engineer protected systems except where legally permitted;
  • introduce malicious code;
  • interfere with service availability;
  • impersonate another user;
  • falsify detection information;
  • use stolen credentials; or
  • conduct unlawful surveillance.

46. CUSTOMER INSTRUCTIONS

Where LIVE AWARE acts as processor, the Customer is responsible for ensuring that its instructions are lawful.

LIVE AWARE may refuse, suspend or request clarification regarding an instruction where it reasonably believes that complying would violate applicable law, contractual requirements or security obligations.

47. DATA SUBJECT RIGHTS

Depending upon applicable law and circumstances, individuals may have rights concerning their personal information, potentially including rights of:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent; and
  • complaint to a competent supervisory authority.

These rights are subject to statutory conditions, limitations and exemptions.

Where LIVE AWARE acts solely as processor, requests concerning Customer-controlled information may need to be directed to the relevant Customer.

48. REQUESTS RECEIVED BY LIVE AWARE

Where LIVE AWARE receives a request concerning information for which a Customer is controller, LIVE AWARE may refer the requester to the relevant Customer and may assist the Customer as required under applicable contractual and legal obligations.

49. DELETION REQUESTS

Deletion is not necessarily absolute or instantaneous.

Information may lawfully remain where retention is necessary for:

  • compliance with law;
  • establishment or defence of legal claims;
  • security;
  • fraud prevention;
  • exercise of legal rights;
  • contractual recordkeeping; or
  • temporary backup retention.

50. WITHDRAWAL OF CONSENT

Where processing is genuinely based upon consent, withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.

Other processing may continue where another lawful basis applies.

51. CUSTOMER DATA OWNERSHIP AND ACCESS

As between LIVE AWARE and the Customer, rights in Customer-provided data are governed by the applicable commercial agreement.

Use of a LIVE AWARE-hosted environment means that LIVE AWARE may technically process and access Customer Data as necessary to operate, secure, maintain and support the Services and for other purposes expressly permitted by the applicable agreement or law.

Such technical access does not automatically transfer ownership of Customer Personal Data to LIVE AWARE.

52. CONFIDENTIALITY

Customers must treat non-public detection information as confidential where appropriate.

Customers should restrict access according to role and business need.

53. EXPORTS

Export functionality, where available, does not constitute authorisation to export information unlawfully.

The person initiating an export is responsible for ensuring that the export is authorised and appropriately protected.

54. CUSTOMER DOWNLOADED DATA

Once Customer Data is lawfully exported from systems controlled by LIVE AWARE, LIVE AWARE may no longer control the security, duplication, transmission, retention or subsequent processing of that copy.

The Customer assumes responsibility for Customer-controlled copies.

55. THIRD-PARTY INTEGRATIONS

Customers may elect to integrate the Services with third-party systems.

Information transmitted to a third-party integration becomes subject to that third party’s practices and the Customer’s arrangements with that provider.

LIVE AWARE is not responsible for independent third-party processing outside LIVE AWARE’s control, except where applicable law provides otherwise.

56. CUSTOMER MISCONFIGURATION

LIVE AWARE is not responsible for privacy consequences resulting solely from Customer-controlled configuration decisions, including:

  • excessive retention;
  • excessive permissions;
  • unauthorised exports;
  • incorrect role assignments;
  • insecure integrations;
  • exposed credentials;
  • public dashboards;
  • inappropriate sharing;
  • disabled security controls; or
  • deployment in inappropriate locations,

except to the extent responsibility cannot lawfully be excluded.

57. THIRD-PARTY HARDWARE

LIVE AWARE does not control the design, security or broadcasting behaviour of independent third-party BLE hardware.

Customers are responsible for assessing hardware they choose to deploy with the Services.

58. OPERATING-SYSTEM PROVIDERS

The Mobile Application depends upon operating-system functionality provided by third parties.

Changes introduced by operating-system providers may affect:

  • Bluetooth scanning;
  • permissions;
  • background execution;
  • battery optimisation;
  • notifications;
  • identifier availability; and
  • application functionality.

LIVE AWARE cannot guarantee uninterrupted functionality following third-party operating-system changes.

59. APP STORE PROVIDERS

Distribution of the Mobile Application through an application marketplace does not make the marketplace operator responsible for LIVE AWARE’s processing or make LIVE AWARE responsible for the marketplace operator’s independent privacy practices.

60. SERVICE AVAILABILITY

The Services may occasionally be unavailable due to:

  • maintenance;
  • updates;
  • outages;
  • telecommunications failures;
  • hosting failures;
  • cyberattacks;
  • force majeure;
  • third-party failures;
  • operating-system changes;
  • emergency maintenance; or
  • circumstances outside reasonable control.

Privacy obligations remain subject to applicable law notwithstanding temporary service interruptions.

61. INCIDENT RESPONSE

Where LIVE AWARE becomes aware of a qualifying personal-data breach affecting information for which it has relevant legal responsibilities, LIVE AWARE will take actions required under applicable law and contractual obligations.

Customers remain responsible for incidents occurring within systems or activities under their control.

62. CUSTOMER DUTY TO REPORT SECURITY ISSUES

Customers and users should promptly report suspected:

  • credential compromise;
  • unauthorised exports;
  • unauthorised access;
  • exposed databases;
  • stolen devices;
  • security vulnerabilities; or
  • other suspected incidents.

Customers should avoid publicly disclosing vulnerabilities before LIVE AWARE has had a reasonable opportunity to investigate and remediate them, subject to applicable law.

63. ANONYMISED AND AGGREGATED INFORMATION

Where permitted by law and applicable contractual arrangements, LIVE AWARE may create statistical, aggregated or anonymised information that does not identify individuals.

Such information may be used for purposes including:

  • security;
  • capacity planning;
  • service improvement;
  • reliability analysis;
  • product development;
  • benchmarking; and
  • operational analytics.

Information that remains reasonably capable of identifying an individual will continue to be treated as personal data where required by law.

64. PRODUCT IMPROVEMENT

LIVE AWARE may process appropriate operational and diagnostic information to improve:

  • reliability;
  • security;
  • usability;
  • performance;
  • compatibility;
  • detection algorithms;
  • infrastructure;
  • troubleshooting; and
  • service functionality,

subject to applicable law and contractual limitations.

65. CUSTOMER RESPONSIBILITY FOR PRIVACY NOTICES

Where the Customer collects personal information using the Services, the Customer is responsible for providing its own privacy notice where required.

The Customer must not rely solely upon this LIVE AWARE Privacy Policy as a substitute for a Customer-specific notice where the Customer itself is controller.

66. CUSTOMER RESPONSIBILITY FOR CONSENT

Where consent is required by applicable law, the Customer is responsible for obtaining valid consent for Customer-controlled processing.

Installation of the Mobile Application does not automatically constitute valid consent by every third party whose device may subsequently be detected.

67. NO IMPLIED THIRD-PARTY CONSENT

The fact that a BLE device broadcasts information does not necessarily mean that the device owner has legally consented to every possible collection or use of that information.

Customers are responsible for evaluating their lawful basis.

68. CUSTOMER INDEMNITY

To the maximum extent permitted by applicable law and subject to the applicable commercial agreement, the Customer may be required to indemnify and hold harmless LIVE AWARE, its officers, employees and affiliates against third-party claims, losses, liabilities, damages, penalties, costs and reasonable legal expenses arising from or relating to:

  • unlawful Customer deployment;
  • unlawful Customer instructions;
  • unauthorised surveillance;
  • unlawful exports;
  • Customer security failures;
  • Customer breach of privacy law;
  • Customer misuse of detection information;
  • Customer failure to provide required notices;
  • Customer failure to obtain required consent;
  • Customer breach of confidentiality; or
  • use of the Services contrary to contractual restrictions.

Any indemnification obligation is subject to mandatory applicable law and the governing commercial agreement.

69. LIMITATION OF LIABILITY

To the fullest extent permitted by applicable law, LIVE AWARE shall not be liable for indirect, incidental, consequential, special or punitive losses arising solely from Customer-controlled misuse, unlawful deployment, unauthorised exports, incorrect interpretation of BLE data or Customer security failures.

Nothing in this Privacy Policy excludes or limits liability where such exclusion or limitation is prohibited by law.

Any contractual liability caps or exclusions applicable to the Services are principally governed by the applicable Terms of Service, licence agreement, order form or other commercial agreement.

70. NO WAIVER OF STATUTORY RIGHTS

No provision of this Privacy Policy should be interpreted as requiring an individual to waive a statutory data-protection right that cannot lawfully be waived.

Similarly, no contractual provision purporting to eliminate all legal claims will apply where such exclusion is prohibited by mandatory law.

71. REFUNDS

Payments, subscriptions, licence charges and refunds are governed by the applicable commercial agreement, subscription terms, order form, Terms of Service and mandatory consumer law.

Except where required by applicable law or expressly provided in the applicable agreement, fees paid for access to or use of the Services are non-refundable.

Installation or use of the Mobile Application constitutes acceptance of applicable contractual terms where those terms have been validly presented and accepted.

Nothing in this Privacy Policy removes any mandatory refund or consumer right that cannot legally be excluded.

72. CLAIMS ARISING FROM CUSTOMER USE

To the maximum extent permitted by law, LIVE AWARE is not responsible for claims resulting from decisions made independently by a Customer using detection information, including Customer employment, security, operational, disciplinary, access-control or investigative decisions.

Customers must independently verify information where appropriate before taking materially adverse action against an individual.

73. CUSTOMER RESPONSIBILITY FOR REGULATORY COMPLIANCE

The Customer is responsible for determining which laws apply to its deployment.

Depending upon location and use case, relevant requirements may concern:

  • privacy;
  • data protection;
  • electronic communications;
  • employment;
  • workplace monitoring;
  • surveillance;
  • cybersecurity;
  • telecommunications;
  • consumer protection;
  • accessibility;
  • discrimination;
  • records management; and
  • sector-specific regulation.

74. DATA PROTECTION IMPACT ASSESSMENTS

Certain deployments involving systematic monitoring, large-scale tracking, vulnerable individuals, sensitive locations or other elevated privacy risks may require a data-protection impact assessment or equivalent assessment.

The Customer is responsible for determining whether such an assessment is required for Customer-controlled processing.

LIVE AWARE may provide reasonable information regarding its processing where required by applicable law or contract.

75. PRIVACY BY DESIGN

Customers are encouraged to configure deployments according to privacy-by-design and privacy-by-default principles.

This may include:

  • minimising collected identifiers;
  • limiting retention;
  • limiting detection areas;
  • restricting administrator access;
  • disabling unnecessary exports;
  • separating datasets;
  • applying pseudonymisation;
  • implementing encryption;
  • reviewing access logs; and
  • regularly reviewing whether continued collection remains necessary.

76. ACCOUNT TERMINATION

Following termination of a Customer account, Customer Data may be deleted or made inaccessible according to contractual terms, retention procedures and legal requirements.

Customers are responsible for obtaining authorised copies they lawfully require before applicable deletion deadlines.

77. SUSPENSION

LIVE AWARE may suspend access where reasonably necessary to:

  • protect security;
  • prevent abuse;
  • respond to a suspected compromise;
  • comply with law;
  • protect third parties;
  • investigate misuse; or
  • enforce contractual rights.

Suspension does not transfer responsibility for Customer-controlled processing to LIVE AWARE.

78. LEGAL HOLDS

LIVE AWARE may preserve information otherwise scheduled for deletion where reasonably necessary to comply with a legal hold, court order, regulatory obligation or the establishment, exercise or defence of legal claims.

79. LAW-ENFORCEMENT REQUESTS

LIVE AWARE may respond to valid legal process.

The Customer acknowledges that absolute confidentiality cannot be guaranteed where disclosure is legally compelled.

80. GOVERNMENT ACCESS

Where legally permissible, LIVE AWARE will seek to handle government requests in accordance with applicable law.

LIVE AWARE does not voluntarily grant unrestricted governmental access to Customer Data merely by virtue of operating the Services.

81. CHANGES TO THE SERVICES

The Services may evolve.

Features may be added, modified or removed.

Where a material change alters how LIVE AWARE processes personal information, this Privacy Policy may be updated and additional notice may be provided where required by law.

82. CHANGES TO THIS PRIVACY POLICY

LIVE AWARE may amend this Privacy Policy from time to time.

The “Last Updated” date identifies the latest published revision.

Material changes will be communicated in a manner appropriate to the circumstances and applicable legal requirements.

Continued use after a change may constitute acceptance of contractual changes where permitted by law, but will not substitute for consent where applicable law specifically requires fresh consent.

83. CONFLICT WITH CUSTOMER AGREEMENTS

Where a separate signed agreement or Data Processing Agreement expressly governs processing between LIVE AWARE and a Customer, that agreement will control to the extent of any irreconcilable conflict, subject to applicable law.

84. SEVERABILITY

If any provision of this Privacy Policy is found invalid, unlawful or unenforceable, that provision will be interpreted or limited to the minimum extent necessary so that the remaining provisions can continue in effect where legally permissible.

85. NO IMPLIED WAIVER

Failure by LIVE AWARE to enforce a contractual right on one occasion does not necessarily constitute a waiver of that right on another occasion.

86. THIRD-PARTY RIGHTS

Except where expressly stated or required by law, this Privacy Policy does not create contractual rights for third parties.

Data subjects nevertheless retain all rights independently granted to them by applicable privacy legislation.

87. ENTIRE PRIVACY FRAMEWORK

This Privacy Policy should be read together with, as applicable:

  • the LIVE AWARE Terms of Service;
  • software licence terms;
  • Customer order forms;
  • Data Processing Agreements;
  • cookie notices;
  • subprocessor information;
  • security documentation; and
  • Customer-specific privacy notices.

88. UNITED KINGDOM DATA PROTECTION LAW

Where applicable, processing may be governed by the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations and other applicable UK legislation as amended from time to time.

Customers operating internationally may also be subject to the laws of other jurisdictions.

89. SUPERVISORY AUTHORITY

Individuals may have the right to lodge a complaint with the competent data-protection supervisory authority.

In the United Kingdom, the relevant supervisory authority is generally the Information Commissioner’s Office (“ICO”).

Nothing in this Privacy Policy is intended to interfere with a legally protected right to contact a regulator.

90. GOVERNING LAW

Subject to mandatory laws that require otherwise, this Privacy Policy and matters relating to the Services shall be governed by the laws of England and Wales.

91. JURISDICTION

Subject to mandatory statutory rights and any applicable contractual dispute-resolution provisions, disputes concerning LIVE AWARE shall be subject to the jurisdiction specified in the applicable Terms of Service or commercial agreement.

Where no separate provision applies, the courts of England and Wales shall have jurisdiction to the extent permitted by law.

92. CUSTOMER ACKNOWLEDGEMENTS

By installing, accessing, activating, configuring or using the Services, the Customer acknowledges that:

  1. BLE technology may detect signals broadcast by devices located nearby.
  2. Such detections may constitute or generate personal data depending upon context.
  3. LIVE AWARE does not determine the Customer’s independent business purposes for deploying BLE detection.
  4. The Customer is responsible for assessing the legality of its deployment.
  5. The Customer is responsible for providing required notices and obtaining required permissions or consents.
  6. BLE proximity information may be inaccurate and must not automatically be treated as proof of exact physical location.
  7. Third-party devices may be detected without direct interaction with the Mobile Application.
  8. Customer administrators may have access to information collected through the Customer environment.
  9. In hosted deployments, LIVE AWARE may process and technically access Customer Data where reasonably necessary to operate, secure, maintain and support the Services and as otherwise permitted by contract or law.
  10. In genuinely isolated stand-alone or on-premise deployments, LIVE AWARE may have no routine access to Customer Data.
  11. Users must not export protected Customer Data outside the authorised environment except where expressly authorised.
  12. The Customer is responsible for exported copies of Customer Data within its control.
  13. The Customer is responsible for the actions of authorised users to the extent provided by applicable law and contract.
  14. The Customer must implement reasonable technical and organisational safeguards.
  15. The Customer must not use the Services for unlawful surveillance, stalking, harassment or discrimination.
  16. The Customer must not rely solely on BLE detections for high-risk decisions without appropriate safeguards.
  17. The Services cannot guarantee detection of every nearby BLE device.
  18. LIVE AWARE cannot guarantee that proximity estimates are physically exact.
  19. Availability of a software feature does not constitute legal advice that the feature may lawfully be used in every jurisdiction.
  20. No provision of this Privacy Policy excludes mandatory rights or liabilities that applicable law does not permit the parties to exclude.

93. USER ACKNOWLEDGEMENT REGARDING CONFIDENTIALITY AND EXPORT

Each authorised user accessing Customer-controlled detection information acknowledges that such information may be confidential and privacy-sensitive.

The user agrees not to knowingly:

  • disclose it to unauthorised persons;
  • export it outside authorised systems;
  • publish it;
  • use it for personal purposes;
  • use it to harass or discriminate;
  • attempt to identify persons without legitimate authority;
  • combine it with unauthorised external datasets;
  • circumvent access controls; or
  • otherwise process it contrary to Customer instructions or applicable law.

94. CUSTOMER ACCEPTANCE OF RESPONSIBILITY

To the fullest extent permitted by applicable law, the Customer accepts responsibility for the Customer’s selection, configuration, deployment and use of the Services and for Customer-controlled processing undertaken through them.

The Customer remains responsible for determining whether the Services are suitable for its intended purpose.

LIVE AWARE provides technological capabilities but does not assume responsibility for the Customer’s independent legal basis, business decisions or unlawful use.

95. NO LEGAL ADVICE

Information provided through the Services, documentation or this Privacy Policy does not constitute legal advice to Customers.

Customers are responsible for obtaining independent professional advice concerning their specific deployment where appropriate.

96. MAXIMUM LAWFUL PROTECTION

Every disclaimer, limitation, allocation of responsibility, indemnity and exclusion contained in this Privacy Policy is intended to operate to the maximum extent permitted by applicable law.

Where applicable law prevents a provision from operating to its full stated extent, the provision shall apply to the maximum lawful extent rather than being interpreted as eliminating protections that can lawfully remain effective.

97. CONTACT DETAILS

Questions concerning this Privacy Policy or LIVE AWARE’s processing of personal information may be directed to:

LIVE AWARE LTD
128 City Road
London
EC1V 2NX
United Kingdom

Company Number: 17360063

A dedicated privacy or data-protection email address should be inserted here before publication:

Privacy Email: [INSERT PRIVACY EMAIL ADDRESS]

Where the inquiry relates to processing controlled by a LIVE AWARE Customer, the individual may need to contact that Customer directly.

98. FINAL ACKNOWLEDGEMENT

By installing, activating, accessing or using the Services after being presented with the applicable terms and notices, the Customer and authorised user acknowledge that they have had an opportunity to review the applicable documentation.

The Customer acknowledges in particular that BLE detection technology can collect technical signals from devices located within detectable proximity and that deployment of such technology can create significant privacy obligations.

The Customer therefore accepts responsibility, to the maximum extent permitted by applicable law, for ensuring that its deployment, purposes, configurations, authorised users, retention practices, exports, disclosures and subsequent uses of Customer-controlled BLE Detection Data comply with applicable law.

LIVE AWARE’s provision of the underlying technology does not constitute an instruction, recommendation or representation that any particular monitoring or tracking activity is lawful.

END OF PRIVACY POLICY

Scroll to Top