Legal

Privacy Policy

Effective date: 21 April 2026

1.Introduction

LIVE Legacy (Pty) Ltd ("LIVE", "we", "us", "our") operates the LIVE platform at livelegacy.ai — a service that allows individuals to record personal video messages and arrange for their secure delivery to nominated recipients after their passing.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and what rights you have over it. It applies to all users of the LIVE platform, including vault owners, executors, and recipients.

LIVE is committed to compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") as it applies to the processing of personal information of South African data subjects, and with the General Data Protection Regulation ("GDPR") as it applies to personal data of individuals in the European Economic Area and the United Kingdom.

By creating an account or using our service, you confirm that you have read and understood this policy. If you do not agree, please do not use LIVE.

2.Who We Are (Responsible Party / Data Controller)

For the purposes of POPIA, the Responsible Party is LIVE Legacy (Pty) Ltd, a South African private company and subsidiary of Dream Merchant Group.

For the purposes of GDPR, LIVE acts as the Data Controller in respect of personal data it collects directly from users.

Information Officer (POPIA)Cybil Rockefeller
Emailprivacy@livelegacy.ai
Supportsupport@livelegacy.ai
JurisdictionRepublic of South Africa

3.What Personal Information We Collect

We collect the following categories of personal information:

Account information

  • Full name and email address (provided at registration)
  • Password (stored as a hashed value — we never see your plaintext password)
  • Profile preferences including check-in interval and subscription tier

Video content

  • Video files you upload to your vault — these may contain images, voices, and any personal content you choose to record
  • Video titles and descriptions you assign
  • Technical metadata: file size, duration, upload timestamp

Recipient information

  • Names, email addresses, and relationship descriptions of people you nominate to receive your videos
  • This constitutes third-party personal information — you are responsible for ensuring you have the right to provide it

Executor information

  • Names, email addresses, and relationship descriptions of people you nominate as executors
  • Portal access tokens associated with each executor

Death verification records (special category data)

  • Death certificates or other documentation uploaded by an executor when confirming a passing — this constitutes health-related or status information and is treated as special category personal information under POPIA and GDPR
  • The identity and name of the confirming executor
  • Timestamps of verification actions

Payment information

  • Subscription tier and billing status
  • Payment processing is handled entirely by PayFast. LIVE does not store card numbers, bank account details, or any raw payment data

Usage and technical data

  • Check-in timestamps and overdue status
  • Video view records (when recipient views a video, how many times)
  • IP addresses and browser/device information collected automatically when you use the platform
  • Server logs retained for security and debugging

5.How We Use Your Information

We use the personal information we collect to:

  • Create and maintain your account and vault
  • Store and secure your video messages until the conditions for release are met
  • Send check-in reminders and escalation notifications
  • Notify your executor(s) when action is required
  • Deliver video messages to nominated recipients upon verified death or inactivity
  • Process subscription payments via PayFast
  • Provide customer support
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with applicable legal obligations
  • Improve the platform based on anonymised usage patterns

We do not use your personal information for advertising, profiling, or sale to third parties. We do not train AI or machine learning models on your video content.

6.Third-Party Processors

We share personal information with a limited set of trusted service providers who process data on our behalf. All processors are bound by data processing agreements and are required to maintain appropriate security standards.

Supabase (supabase.com)Database, authentication, and row-level security. Hosted on AWS infrastructure in the EU (eu-west-2). EU Standard Contractual Clauses apply.
Cloudflare R2 (cloudflare.com)Encrypted video and document storage. Data stored in Cloudflare's global network. Cloudflare's DPA and SCCs apply.
PayFast (payfast.co.za)Payment gateway for subscription billing. PayFast processes card and EFT payments on our behalf — their privacy policy governs their handling of payment data.
Resend (resend.com)Transactional email delivery. Email addresses and message content are processed to deliver emails on our behalf.
Vercel (vercel.com)Application hosting and serverless functions. Request logs and IP addresses may be processed. Vercel DPA applies.

We do not share your personal information with any other third parties except where required by law or with your explicit consent.

7.International Data Transfers

LIVE is a South African company, but our infrastructure providers operate globally. Personal information may be transferred to and processed in countries outside of South Africa and the EEA, including the United States, where data protection laws may differ.

Where such transfers occur, we ensure appropriate safeguards are in place:

  • EU Standard Contractual Clauses (SCCs) for transfers from the EEA to third countries
  • Data Processing Agreements with all processors containing transfer provisions
  • Where applicable, we rely on the adequacy decisions of the European Commission or the Information Regulator of South Africa

8.How Long We Keep Your Data

Account informationRetained for the life of your account, plus 30 days after deletion to allow for recovery
Video contentRetained until you delete the video, your account is deleted, or (if released) until the release token expires (1 year after release)
Recipient and executor dataRetained for the life of the associated video or account
Death certificatesRetained for 7 years following a verified release, to support legal and estate administration needs
Payment recordsRetained as required by South African tax law (minimum 5 years)
Server and security logsRetained for up to 90 days
Check-in logsRetained for the life of the account

When you delete your account, we delete or anonymise all personal information except where retention is required by law or to complete an ongoing service obligation (e.g., a released vault where recipients hold valid tokens).

9.Security

We take the security of your personal information seriously. Given that your vault may contain deeply personal content, we have implemented the following safeguards:

  • All video and document storage in Cloudflare R2 is private — no object is publicly accessible. Recipients access content exclusively via short-lived signed URLs
  • Recipient watch links and executor portal links are cryptographically random 64-character tokens
  • Database access is governed by Row Level Security policies — each authenticated user can only access their own data
  • All data in transit is encrypted using TLS 1.2 or higher
  • Authentication is managed by Supabase — passwords are hashed and salted; we never store or see plaintext credentials
  • Service Role keys (which bypass RLS) are stored only in server-side environment variables, never exposed to the client

No security system is impenetrable. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by applicable law.

10.Your Rights

Depending on your location, you have some or all of the following rights regarding your personal information:

Right of accessRequest a copy of the personal information we hold about you
Right to correctionRequest correction of inaccurate or incomplete information
Right to deletion / erasureRequest deletion of your personal information, subject to legal retention requirements
Right to objectObject to processing based on legitimate interest (including direct marketing, if any)
Right to restrict processingRequest that we limit how we use your data in certain circumstances (GDPR)
Right to data portabilityReceive a copy of your data in a structured, machine-readable format (GDPR)
Right to withdraw consentWhere processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
Right to complainLodge a complaint with a supervisory authority

For South African users (POPIA)

You may direct complaints to the Information Regulator of South Africa: www.inforegulator.org.za

For EU/EEA users (GDPR)

You have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.

Exercising your rights

To exercise any of these rights, email us at privacy@livelegacy.ai. We will respond within 30 days. We may need to verify your identity before processing your request.

11.A Note on Recipient and Executor Data

When you add a recipient or executor to your vault, you are providing us with personal information about another individual. By doing so, you confirm that:

  • You have a legitimate basis for sharing their information with us (e.g., their knowledge and agreement)
  • The information is accurate to the best of your knowledge
  • You understand that we will contact them in connection with your vault

Recipients receive a welcome email when you add them to a video, informing them that a message has been stored for them and that they will receive it when the time comes. They are not required to create an account or provide any information to LIVE at that stage.

Recipients who wish to have their information removed from a vault should contact the vault owner directly, or contact us at privacy@livelegacy.ai if the vault owner is deceased and the matter is urgent.

12.Cookies and Tracking

LIVE uses only functional cookies necessary to operate the platform. These include:

  • Authentication session cookies (managed by Supabase) — required to keep you logged in
  • Security cookies to prevent cross-site request forgery

We do not use advertising cookies, tracking pixels, or third-party analytics services that profile your behaviour. We do not use Google Analytics or similar services.

13.Children

LIVE is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has registered for an account, please contact us at privacy@livelegacy.ai and we will promptly delete the account and associated data.

14.Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and, for material changes, send you a notification email.

Continued use of LIVE after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree to the updated policy, you should delete your account before the revised policy takes effect.

15.Contact Us

For any privacy-related questions, requests, or concerns, please contact our Information Officer:

NameCybil Rockefeller (Information Officer)
Privacy enquiriesprivacy@livelegacy.ai
General supportsupport@livelegacy.ai
CompanyLIVE Legacy (Pty) Ltd
Supervisory authority (SA)Information Regulator — www.inforegulator.org.za
LIVE — Legacy In Video Eternity · livelegacy.ai