Skip to main content

GDPR Compliance

How Livin Services complies with the UK and EU GDPR: where we act as controller versus processor, our Article 28 commitments, the DPA, transfer mechanisms, and how a rights request is handled.

Last updated 31 July 2026Governed by the laws of England and Wales

In plain English

  • We are the controller for data about you as a business contact, and the processor for your customers’ data we touch during a project.
  • We will sign a data processing agreement before any project involving personal data — ours or yours.
  • We never use personal data found in your systems for our own purposes, and never as training data.
  • Transfers outside the UK and EEA use the IDTA or the EU SCCs with the UK Addendum, plus encryption and minimised access.
  • Rights requests get a substantive answer within one month, free, from a person rather than a ticket queue.
  • We have not appointed a statutory DPO and hold no ISO or SOC certification — and we would rather say so than imply otherwise.

This summary is for orientation only. The numbered terms below are the ones that apply.

1. Scope of this statement

This statement explains how Livin Services complies with the UK General Data Protection Regulation, the EU General Data Protection Regulation, and the UK Data Protection Act 2018. It is written for the person who has to sign us off — a client, a legal team, or a procurement function — and it is intended to answer their questions without a call.

It supplements rather than replaces our privacy policy. What personal data we collect, why, and precisely how long we keep each type is stated in that document, and stated there only. Cookies are covered in the cookie policy. Duplicating those facts here would guarantee that one copy eventually contradicted the other.

2. Our two roles: controller and processor

Almost every question about our GDPR position resolves once this distinction is clear, so it comes first.

We are the CONTROLLER for data about you as a business contact: your enquiry, our correspondence, the scope and the contract, invoicing, and any role application, referral or partnership proposal. We decide why and how that data is used, and our privacy policy governs it.

We are the PROCESSOR for personal data belonging to your customers, users or staff that we handle while delivering your project — order records, mailing lists, user accounts, support histories, analytics belonging to your property. You decide why and how that data is used; we act on your instructions.

The practical consequence of being your processor is that your obligations do not become ours by default and ours do not become yours. A rights request from one of your customers goes to you, not to us — and we will support you in answering it.

3. What we commit to as your processor

These are the Article 28 obligations, stated as what we will actually do rather than as a restatement of the legislation.

  • We process your data only on your documented instructions, and we will tell you if an instruction appears to us to breach data protection law.
  • We never use personal data we encounter in your systems for our own purposes. It does not enter a list of ours, it is not used to market to anyone, and it is not used as training data.
  • Everyone with access is bound by confidentiality obligations that survive the end of the engagement.
  • We apply access controls scoped to named individuals, encryption in transit and at rest, and two-factor authentication on every account that supports it.
  • We will not engage a sub-processor for your project without telling you, and we remain responsible for their performance.
  • We assist you with data subject requests, data protection impact assessments and regulator enquiries relating to the work we did.
  • We notify you without undue delay on becoming aware of a personal data breach affecting your data, with what we know rather than a holding statement.
  • On the conclusion of the engagement we delete or return your data as you direct, subject only to records we are legally required to keep.
  • We make available the information you reasonably need to demonstrate compliance, and we will accept a proportionate audit right in the agreement.

4. Data processing agreement

We will sign a data processing agreement before any project that involves us handling personal data on your behalf. Ask and we will provide ours, which reflects section 3 above; or send yours and we will review it.

We will not sign a DPA that describes controls we do not have. It is quicker to tell you what we actually do and let you decide whether it is sufficient than to agree to something and be found short of it during an audit — and a warranty we cannot honour is worth nothing to you.

Where a project genuinely requires it, we will complete your security questionnaire and support a data protection impact assessment. Raise these during scoping rather than after: data minimisation, pseudonymisation and residency constraints are inexpensive design decisions and expensive retrofits.

5. Lawful bases

As controller, our lawful basis for each purpose is set out in full in section 5 of our privacy policy — contract, legal obligation, legitimate interests, or consent, stated purpose by purpose.

Two points worth drawing out here. First, we rely on consent only for optional cookies and for the newsletter, both of which are opt-in and withdrawable, so nothing important to your engagement depends on a consent that could be withdrawn. Second, we carry out no automated decision-making or profiling that produces legal or similarly significant effects.

6. International transfers

We operate from Islamabad, Pakistan and Birmingham, United Kingdom. Some of our service providers are established in the United States or elsewhere. Personal data may therefore leave the UK and the European Economic Area.

Neither Pakistan nor the United States benefits from a general UK or EU adequacy decision, so we do not rely on adequacy. For restricted transfers we use the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, whichever is appropriate to the exporting jurisdiction and the parties involved.

Alongside the contractual instrument we apply supplementary measures: encryption in transit and at rest, access limited to named individuals who need it for the specific engagement, and holding the minimum data the work requires so that the volume exposed to any transfer is as small as possible.

We will confirm the mechanism applying to a specific transfer, and identify the receiving provider, on request. If you require data to remain within the UK or the EEA, say so before we scope the work — it is achievable, and it constrains which providers we can use.

7. Sub-processors

We use third-party providers for hosting and content delivery, email and productivity, messaging, payments and accounting, version control and cloud infrastructure, and — subject to your consent as a website visitor — analytics. The categories and their purposes are listed in section 6 of our privacy policy.

Each is bound by a written agreement requiring it to act only on our instructions, maintain appropriate security, and delete or return data on request.

We will name the specific provider in any category on request, and for client engagements we will list the sub-processors touching your project in the DPA. We do not publish a live public list, because a list that is three months stale is more misleading than no list — it invites reliance on information that is wrong.

8. Individual rights, and how to exercise them

Where we are the controller, you have the rights set out in section 11 of our privacy policy: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority.

To make a request, email contact@livinservices.com with enough detail to identify what you are asking for. You can also reach us on WhatsApp at +92 337 0330012 (Pakistan) or +44 7588 219953 (United Kingdom) — both numbers, because listing only one was an inconsistency in the previous version of this page.

  • We acknowledge a request promptly and respond substantively within one calendar month.
  • If a request is complex or there are several, we may extend by up to two further months — and we will tell you inside the first month if that applies, with the reason.
  • We do not charge a fee, unless a request is manifestly unfounded or excessive, in which case we will explain our reasoning before charging anything and give you the chance to narrow it.
  • We may ask you to verify your identity first. That protects you: disclosing your data to someone impersonating you would be the more serious failure.
  • Where we cannot fully comply — for example where accounting records must be retained by law — we will tell you exactly which data we are keeping and under what obligation, rather than refusing in general terms.
  • Where we are the processor and the request concerns your customers’ data, we will pass it to you promptly and help you answer it.

9. Breach notification

Where we are the controller and a personal data breach is likely to result in a risk to individuals’ rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we notify affected individuals without undue delay where the risk is high.

Where we are your processor, we notify you without undue delay on becoming aware, with the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. Your notification obligations to the authority and to individuals remain yours, and we will give you what you need to meet them.

We will not delay a notification in order to complete an investigation first. You will get what we know when we know it, updated as the picture develops.

10. Supervisory authority and complaints

If you are unhappy with how we have handled your personal data, tell us first — most issues are a misunderstanding and we would rather correct it than have it escalate.

You do not have to come to us first. You may complain directly to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113). In the EEA it is the authority in your country of residence, place of work, or where the alleged infringement occurred.

We do not require you to exhaust an internal process, and we will not treat making a complaint as a breach of any agreement between us.

11. Accountability, and the honest limits

We maintain records of our processing activities, we assess new tools before adopting them, we design projects to collect the minimum personal data the objective requires, and we keep consent records that can demonstrate consent was actually given.

We are not required to appoint a statutory Data Protection Officer under Article 37, and we do not claim one. Data protection is handled by the company directors. Naming a DPO we had not appointed would be the kind of small inaccuracy that undermines everything else in this document.

We hold no ISO 27001 or SOC 2 certification, and we will not imply otherwise. Our security practices page describes what we genuinely do. If your procurement process requires a certified supplier, we would rather you knew now than after a scope was agreed.

Any question this page does not answer, ask: contact@livinservices.com. A specific answer by email is worth more to your legal team than another paragraph here.

Questions about this document

Ask us before you sign anything. We would rather explain a clause than have you agree to something you are not comfortable with.

Pakistan Office
DHA Phase 1, Islamabad
Pakistan
United Kingdom Office
Broad Street, Birmingham
United Kingdom